Privacy

Privacy Policy

What we collect, why, who else sees it, and how to get it removed. Written plainly, because this is information about how you feel.

Last updated: 9 September 2026

A note before you read: this text was drafted with AI as a strong starting point. It should still be reviewed by a legal professional before final launch, and it is not finished legal advice.

1. Who is responsible for your data

InnerPath ("InnerPath", "we", "us") is the data controller for the personal data described in this policy. InnerPath operates the website myinnerpath.eu and the 21-day reset offered through it.

For any privacy question, request or complaint, you can write to privacy@myinnerpath.eu. We aim to reply within 30 days, as required under the GDPR.

If you believe we have handled your data incorrectly, you also have the right to lodge a complaint with the data protection authority in your country of residence.

2. What personal data we collect

Intake answers. When you start a reset, you answer a short intake about your energy, sleep, stress, available time, what is currently weighing on you, and what you would like to change. We treat these answers honestly for what they are: sensitive information about your wellbeing. They are only used to build and adapt your plan, and they are never sold, rented or shared for advertising.

Daily reflections and feedback. What you write at the end of a day, how a day felt, and any dreams or notes you record. This is also wellbeing-related information and is treated with the same care as your intake answers.

Account details. Your email address, and — if you sign in with Google — the basic profile information Google returns (name, email, profile image). Passwords are stored only in hashed form by our authentication provider; we never see them.

Payment details. When paid access is enabled, the one-time payment of €29 is handled by an external payment provider. We receive confirmation that a payment succeeded and basic transaction data, but we do not store your full card number.

Chatbot messages. Messages you send to Will, the assistant on the site, together with the answers returned.

Basic usage data. Technical information such as pages visited, approximate region, browser type and error logs, used to keep the site working and to understand which pages are useful.

3. Why we use your data, and on what legal basis

To generate your personalised 21-day plan. Your intake answers, reflections and daily feedback are used to build each day and to adapt the following days. Legal basis: performance of the service you sign up for (Article 6(1)(b) GDPR), and your explicit consent for the wellbeing-related details you choose to share (Article 6(1)(a) and Article 9(2)(a) GDPR).

To operate the chatbot. Your messages are used to answer questions about InnerPath. Legal basis: performance of the service and your consent in choosing to use the chat.

To manage your account and payment. Legal basis: performance of a contract and our legal obligations, such as keeping accounting records.

To keep the site secure and working. Legal basis: our legitimate interest in operating a reliable, secure service.

You can withdraw your consent at any time by deleting your account or by writing to privacy@myinnerpath.eu. Withdrawing consent does not affect processing that already took place.

4. Third parties who process data for us

Anthropic (Claude API). Your intake answers, daily feedback and chatbot messages are sent to Anthropic's Claude API so it can generate personalised plan content and answer your questions. Anthropic acts as a processor on our behalf and is not permitted to use your data for its own purposes.

Transfers outside the EU. This processing may involve transferring data to servers outside the European Economic Area, including the United States. Where that happens, the transfer is covered by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and additional technical and organisational measures.

Hosting, database and authentication. The site and your account data are hosted with our infrastructure providers, who process data only on our instructions.

Payment provider. When paid access is enabled, an external payment provider processes your payment as an independent controller for the payment itself.

We do not sell your personal data, and we do not share it with advertisers.

5. How long we keep your data

Account, intake answers, plan content and reflections are kept for as long as your account exists, so you can reread your reset. If you delete your account, this data is deleted from our systems, with backups cycling out within 30 days.

If you stop using InnerPath without deleting your account, we delete inactive accounts and their content after 24 months of inactivity, after a reminder by email.

Chatbot messages are kept for up to 12 months to monitor quality and abuse, then deleted.

Payment and invoice records are kept for as long as tax and accounting law requires, normally seven years.

6. Your rights under the GDPR

Access. You can ask for a copy of the personal data we hold about you.

Correction. You can ask us to correct data that is wrong or incomplete.

Deletion. You can ask us to delete your account and the data connected to it.

Portability. You can ask for your intake answers, plan and reflections in a common, machine-readable format, or ask us to send them to another provider.

Objection and restriction. You can object to processing based on our legitimate interests, and ask us to restrict processing while a request is being handled.

Withdrawing consent. Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, write to privacy@myinnerpath.eu from the email address linked to your account. We will not charge you for a reasonable request.

7. Cookies and analytics

We use a small number of strictly necessary cookies and similar browser storage to keep you signed in and to remember where you are in your reset. These are required for the site to work and cannot be switched off.

We use privacy-friendly, aggregated usage measurement to understand which pages are visited. We do not use advertising cookies, tracking pixels or cross-site profiling. If we ever introduce non-essential cookies, we will ask for your consent first.

8. Children

InnerPath is not intended for children. The service is only for people aged 16 or older. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, write to privacy@myinnerpath.eu and we will delete it.

9. Security

Data is transmitted over encrypted connections and stored in access-controlled systems. Your plan, reflections and intake answers are readable only by your own account. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.

10. Changes to this policy

We may update this policy as the service develops. The current version is always available on this page. If a change materially affects how we use your data, we will let you know by email or through the site.

Privacy questions? Write to privacy@myinnerpath.eu.