Privacy Policy
Last updated: March 13, 2026
1. Who We Are
fayth.life ("we", "us", "our") provides a free, evidence-based ADHD screening tool for adults. This policy explains how we collect, use, store, and protect your personal data.
2. Data We Collect
We collect the following categories of data:
- Identity data: Name (optional), age, gender, email (optional)
- Screening data: DSM-5 questionnaire responses, context responses, follow-up responses
- Cognitive task data: Go/No-Go scores, Chronos Sort scores, Focus Quest scores (reaction times, accuracy metrics, composite indices)
- Technical data: Browser type, session identifiers
Sensitive data: Your screening responses and cognitive task results constitute mental health-related data. We treat this data with the highest level of protection.
3. How We Use Your Data
- To generate your personalized ADHD screening report
- To tailor follow-up questions based on your gender
- To allow you to view past assessment history (if signed in)
- To send one-time verification codes to your email (if you choose to sign in)
We do not sell, rent, or share your data with third parties for marketing purposes.
4. Lawful Basis for Processing (GDPR)
We process your data based on:
- Consent: You explicitly consent before starting the assessment
- Legitimate interest: To provide and improve the screening service
You may withdraw consent at any time by deleting your data (see Section 7).
5. Data Storage & Security
- Client-side: Assessment data is stored in your browser's session/local storage for continuity during the assessment
- Server-side: If you complete the assessment, results may be stored in our database (Supabase, hosted on AWS with encryption at rest)
- Authentication: We use Google OAuth and email OTP verification via Supabase Auth
- Transmission: All data is transmitted over HTTPS/TLS
6. Data Retention
We retain your screening data for up to 12 months from the date of your assessment. Anonymous session data (without a linked account) is retained for up to 90 days. You may request earlier deletion at any time.
7. Your Rights
Under GDPR and applicable privacy laws, you have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Withdraw consent: At any time, without affecting prior processing
To exercise any of these rights, contact us at the address below.
8. Third-Party Processors
We use the following third-party services to operate fayth.life:
- Supabase — Database and authentication (hosted on AWS)
- Vercel — Application hosting and deployment
- Google — OAuth authentication provider
Each processor handles data in accordance with their own privacy policies and applicable data protection agreements.
9. Cookies
We use only essential cookies required for the application to function:
- Authentication cookies: Supabase auth session tokens
- OTP cookies: Temporary cookies for email verification (httpOnly, expire in 5 minutes to 24 hours)
We do not use analytics cookies, advertising cookies, or tracking pixels. See our Cookie Policy for details.
10. Children
This service is intended for adults aged 18 and older. We do not knowingly collect data from anyone under 18.
11. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated on this page with an updated "Last updated" date.
12. Contact
For privacy inquiries, data requests, or complaints, contact us at: privacy@fayth.life