Privacy Policy

Effective June 24, 2026

1. Who We Are

Harvey Castro, MD MBA operates the InPsychNow™ platform ("Service"). This Policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

Account data — name, email address, profile photo (via Google OAuth).

Assessment data — your DISC profile responses, Purpose Prism™ answers, Self-Lens™ check-ins, and Operating Vitals™ entries. This data is used solely to generate your personalized recommendations.

Ephemeris data — planetary transit calculations stored per your user ID. No birth location is stored in the database; calculations use approximate reference coordinates and are stored as numeric JSON.

Usage data — pages visited, feature interactions (via PostHog, a privacy-respecting analytics platform). IP addresses are not stored long-term.

Billing data — managed by Stripe. We store only your subscription status and Stripe customer ID. We never see or store raw payment card numbers.

3. How We Use Your Data

We do not sell your personal data. We do not use your data to train AI models.

4. Data Retention

We retain your account and assessment data for as long as your account is active. If you delete your account, your data is purged within 90 days, except where longer retention is required by law or legitimate business need (e.g., billing records).

5. Third-Party Services

6. Cookies

We use session cookies issued by Supabase for authentication. We do not use third-party advertising cookies. You can disable cookies in your browser, but this will prevent you from signing in.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, port, or delete your data. To exercise these rights, email legal@harveycastromd.com. We will respond within 30 days.

You can also delete your account directly from Settings → Account → Delete Account, which initiates immediate anonymization of your profile and queues full deletion within 90 days.

8. Children

The Service is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it promptly.

9. Security

All data is encrypted in transit (TLS) and at rest. Row-Level Security (RLS) is enforced at the database layer — each user can only access their own records. We conduct regular security reviews and follow responsible disclosure practices.

10. Changes to This Policy

We may update this Policy. We will notify you by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance of the updated Policy.

11. Contact

Privacy questions: legal@harveycastromd.com
Harvey Castro, MD MBA · Dallas, TX
https://inpsychnow.com