felt icon
PricingAboutPrivacy

Privacy Policy

We take your privacy seriously and are committed to keeping your information safe

Felt — Privacy Policy

Effective date: August 20, 2026 Last updated: August 20, 2026

Felt is operated by Solae LLC, a Utah limited liability company doing business as "felt" ("Felt," "we," "us," "our").

This policy explains what we collect, why, how long we keep it, and what control you have. Felt handles information about your mental health, so we've tried to write this plainly rather than defensively.

Contact: privacy@felt-emdr.com · 38 E Siena Dr, Pleasant Grove, UT 84062, United States


1. The short version

  • Felt is a self-guided EMDR and trauma-processing practice tool. What you write in a session — the memory you're working on, your beliefs about it, your distress ratings — is the most sensitive data in the product, and we treat it as health data.
  • We do not run analytics, advertising, or third-party tracking on Felt. No ad pixels, no marketing SDKs, no session replay.
  • We do not sell your personal information and do not share it for cross-context behavioral advertising.
  • Your session data is isolated at the database level so that only your account can read it.
  • You can delete your account and all session data yourself, at any time, from Settings → Delete.
  • Felt is for adults only (18+).

2. What we collect

2.1 Account and identity

We use Supabase Auth to sign you in. Depending on the method you choose:

  • Email + password — your email address and a hashed (never plaintext) password.
  • Google sign-in — your Google account email, name, profile picture, and Google account identifier, shared with us by Google when you consent.

We also store your unique user ID, sign-up and sign-in timestamps, whether you have verified your email address, and an authentication session token in a browser cookie.

Verifying your email. Signing up creates your account straight away, so you can begin a session without waiting on an email. Separately, we send you a link to verify your address. Verifying isn't required to use the Service — it's what lets you sign in from another device and reset your password, so we'll keep reminding you until you do. We store only a one-way hash of each verification link, never the link itself, and each one expires after 7 days and can be used once. If you sign in with Google, your address is already confirmed by Google and we don't send you one.

2.2 Profile

  • Disclaimer acknowledgement — the timestamp when you accepted the in-app safety disclaimer.
  • Screening responses (risk_flags) — your answers to the pre-session safety questionnaire. This is health information. We use it to determine whether and how you proceed.
  • Preferences — app and interface settings.
  • Emergency contact — optional. If you choose to save one, we store the name, phone number, and relationship you enter. This is information about another person, so please only add someone who is willing to be contacted. It is never displayed to anyone but you, never contacted by us automatically, and is deleted with your account.
  • Profile photo — optional. If you upload one, the image file is stored in a publicly readable location, which means anyone who has the direct link can view it. The link is not published or indexed by us, but treat an uploaded photo as public rather than private. Only you can upload, replace, or delete files in your own folder. If you don't upload one, we generate a flower avatar from your email address and store no image.
  • Free-trial start date — the date your 7-day trial began, so we can show how much of it remains.
  • Email verification date — when you followed the verification link, if you have.

2.3 Session content — the sensitive core

Each session you run stores:

  • A title you provide, which may reference a memory or event.
  • The session type (e.g. EMDR).
  • Distress and belief ratings you enter before, during, and after the session.
  • Session content — your free-text and structured answers, including intake notes, the target memory or image you're processing, and the associated negative and positive beliefs.
  • Your flower drawing (stored as vector stroke data).
  • Start and completion timestamps.

We also keep point-in-time backups of sessions — JSON snapshots containing the same content — so that an interrupted session can be recovered.

2.4 Waitlist

If you join the waitlist, we store your email address and the date you signed up.

2.5 Contact form

Your name, email address, and message, which are emailed to our support inbox.

2.6 Stored on your device

  • Cookies — your Supabase authentication session, which keeps you signed in. This cookie is strictly necessary to operate the service. We do not use advertising or analytics cookies.
  • localStorage — interface state only: your color theme, display preferences, and which dismissible prompts you've already dismissed. No personal or health data, and none of it leaves your device.

2.7 Collected automatically by our host

Our hosting provider (Vercel) processes standard server and CDN logs, which include your IP address and request metadata, in the course of serving the site. These are ordinary infrastructure logs, not a behavioral profile.


3. How we use your information

PurposeData used
Authenticate you and keep you signed inAccount, auth cookie
Run sessions; save and restore progressSession content, backups
Show your meadow and session historySession content, flower drawings
Safety gating — deciding whether and how you proceedScreening responses, disclaimer acknowledgement
Verify your email so you can recover your accountEmail address, verification link
Reply to youContact-form submissions
Waitlist and product-update emailWaitlist email address
Keep the service secure and operationalIP and request logs

We do not use your session content to train machine-learning models. We do not use it for advertising. We do not profile you or make automated decisions with legal or similarly significant effects about you.


4. Legal bases (GDPR / UK GDPR)

If you are in the EEA, UK, or Switzerland, our legal bases are:

  • Contract (Art. 6(1)(b)) — creating your account, running sessions, storing your history, responding to you.
  • Consent (Art. 6(1)(a)) — marketing and product-update email. Withdraw at any time via the unsubscribe link.
  • Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and keeping the service running.
  • Explicit consent (Art. 9(2)(a)) — for special-category health data. Your session content and screening responses reveal information about your mental health. We process them only on the basis of your explicit consent, given when you accept the in-app disclaimer and begin a session. You can withdraw that consent by deleting your account, which erases the underlying data.

5. Who we share it with

We share personal data only with the service providers below, each acting as our processor under contract. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

ProviderPurposeWhat they receive
SupabaseAuthentication and database hostingAll account, profile, session, backup, and waitlist data
GoogleOAuth sign-inEmail, name, profile picture, Google ID — only if you choose Google sign-in
ResendTransactional and marketing emailRecipient email address; your email-verification link; contact-form name and message
VercelApp hosting, edge compute, CDNAll traffic in transit; IP address and request metadata in logs

We may also disclose information if legally required (subpoena, court order, or law enforcement demand we're compelled to honor), or to protect against imminent harm. Given the sensitivity of session content, we will resist overbroad requests and, where lawfully permitted, notify you before disclosing.

If Felt is ever acquired or transferred, your data may transfer with it. You will be notified beforehand and given the opportunity to delete your account first.


6. Retention and deletion

  • Anonymous accounts — an earlier version of Felt let you start a session without signing up, which created an account with no email address attached. We no longer do this; every account now begins with a sign-up. Any such account left over from that period is deleted automatically after 7 days of inactivity — no sign-in and no session activity in that window — by a scheduled daily job, cascading to its sessions, profile, and backups. We keep an internal log of each run (timestamp and number of accounts deleted; no personal data). An account with an email address on it is never touched by this job.
  • Registered accounts — your profile, sessions, and backups persist until you delete your account.
  • Self-serve deletion — signed-in users can permanently delete their account at Settings → Delete. This removes your uploaded profile photo, then deletes your account and everything attached to it — sessions, backups, profile, screening responses, emergency contact, and any outstanding verification links — and signs you out. This is irreversible.
  • Waitlist entries persist until removed. Contact-form messages persist in our support inbox. Neither is removed by account deletion — email privacy@felt-emdr.com to have them deleted.
  • Backups and logs held by our providers may persist for a short additional period in their routine backup cycles before being overwritten.

7. Security

  • All data is encrypted in transit (TLS) and at rest.
  • Every user table enforces Postgres Row Level Security: a signed-in user can read and write only their own rows. This is enforced by the database itself, not just application code.
  • Passwords are hashed; we never see them.
  • Deleting an account cascades automatically to its profile, sessions, backups, and verification links; the uploaded profile photo is removed separately as part of the same action.
  • Verification links are stored only as a one-way hash, so even we cannot reconstruct a link from the database.

No system is perfectly secure. If a breach affects your unsecured health information, we will notify you and, where required, the FTC and applicable regulators, consistent with the FTC Health Breach Notification Rule and other applicable breach-notification laws.


8. International transfers

Felt is operated from the United States and your data is stored and processed there. If you access Felt from outside the US, you are transferring your data to the US. For EEA/UK/Swiss users, transfers to our providers rely on the EU Standard Contractual Clauses and the UK Addendum, or on an applicable adequacy decision, together with supplementary measures where appropriate.


9. Your rights

Regardless of where you live, you can:

  • Access and export your data — email privacy@felt-emdr.com and we will provide a machine-readable copy of your account, profile, sessions, and drawings.
  • Correct inaccurate information.
  • Delete your account and all session data — instantly, yourself, at Settings → Delete.
  • Opt out of marketing email — unsubscribe link in every message.

If you're in the EEA, UK, or Switzerland, you also have the rights to restriction, objection, portability, withdrawal of consent, and to lodge a complaint with your supervisory authority.

If you're in California, you have the rights to know, delete, correct, and to limit use of sensitive personal information under the CCPA/CPRA. Felt does not sell or share personal information, so there is no opt-out to exercise. Sensitive personal information (your health data) is used only to provide the service you requested — never for inferring characteristics about you. We will not discriminate against you for exercising any right.

If you're in Utah, Colorado, Connecticut, Virginia, Texas, or another state with a comprehensive privacy law, you have equivalent rights of access, deletion, correction, and portability, and — where your state provides one — a right to appeal a denied request by replying to our response.

If you're in Canada, you have rights of access and correction under PIPEDA and may complain to the Office of the Privacy Commissioner.

We respond to requests within 30 days (45 where permitted). We may need to verify your identity, usually by confirming control of your account email. Authorized agents may submit requests on your behalf with written proof.


10. Children

Felt is not for anyone under 18. We do not knowingly collect data from minors. If we learn that a minor has created an account, we will delete it. If you believe a minor is using Felt, contact privacy@felt-emdr.com.


11. Not a medical service

Felt is a self-guided wellness practice tool. It is not a medical device, does not provide diagnosis or treatment, and does not create a clinician–patient relationship. We are not currently a HIPAA covered entity or business associate, and we do not share your data with clinicians. That does not lower our standard of care for this information — it is health data and we treat it as such.

If you are in crisis, contact a licensed professional or call or text 988 (US Suicide & Crisis Lifeline).


12. Changes to this policy

We will post any changes here with an updated date. For material changes to how we handle session content, we will notify you by email and, where the change requires it, ask for your consent again before it takes effect.


13. Contact

Solae LLC (dba felt) · 38 E Siena Dr, Pleasant Grove, UT 84062, United States privacy@felt-emdr.com