Trust & Privacy
This page is maintained by MyelSyn Consulting to answer common security and privacy questions about how we handle your information. It describes the controls currently in place — it is editable content, not an independent certification or third-party audit.
Accounts & authentication
Customer accounts are protected by email-and-password sign-in, with optional Google sign-in where enabled. Passwords are never stored by us — authentication is handled by our managed identity provider, which stores password hashes only.
Administrative access is gated by a separate role and is granted only to MyelSyn staff. Role checks are enforced server-side.
Data we collect
We collect the information you provide directly: your name and email when you create an account or take the assessment, your assessment answers, optional demographic context (industry, organization size, leadership level, geography), and records of any purchases or bookings you make with us.
Assessment submissions made without signing in are stored anonymously and used in aggregate to compute benchmarks. We do not attempt to re-identify anonymous submissions.
How your data is protected
Data is stored in a managed Postgres database with row-level security enabled on user-owned tables, so signed-in users can only read and modify their own records. Downloadable resources are served through short-lived signed URLs from a private storage bucket — there are no public links.
Data is encrypted in transit (HTTPS) and at rest by our infrastructure provider. Administrative credentials and API keys are stored as server-side secrets and are never shipped to the browser.
Payments
Payments are processed by Stripe. We never see or store your full card number, CVC, or bank credentials — that data is handled directly by Stripe's PCI-compliant infrastructure. We retain only the metadata Stripe returns to us (amount, status, receipt URL, customer identifier) so we can show your purchase history and grant access to what you bought.
Email & marketing
Transactional emails (your Narrative Profile, receipts, booking confirmations) are sent through Resend. We rate-limit anonymous email requests to prevent abuse of our send infrastructure.
If you opt in to marketing emails, your contact details are synced to our CRM (Systeme.io). You can unsubscribe at any time using the link at the bottom of any marketing email.
Cookies & analytics
We use only the cookies required to keep you signed in and to remember your preferences. We do not run third-party advertising trackers.
Retention & deletion
You can request deletion of your account and personal data at any time by emailing us at the address below. Anonymous, aggregated assessment data (used for benchmarks) may be retained after account deletion because it can no longer be tied back to you.
Payment records may be retained for as long as required by tax and accounting regulations.
Reporting a security concern
If you believe you have found a security vulnerability or have a privacy concern, please email hello@myelsyn.com with details. We appreciate responsible disclosure and will respond as quickly as we can.
Shared responsibility
MyelSyn Consulting is responsible for the application code, access controls, and how we use your data. Our hosting and infrastructure providers (Cloudflare, Supabase, Stripe, Resend) are responsible for the security of the underlying platforms. You are responsible for keeping your account password confidential and for the accuracy of the information you provide.
This page is app-owned editable content describing current practices. It is not a Lovable-issued certification or independent attestation. For questions, contact hello@myelsyn.com.
