← Back· Innerify

Privacy Policy

Last updated: July 14, 2026.

This policy explains how Smarthink LLC (operator of Innerify) handles your personal data when you use our website and services. It's written in plain language. If something isn't clear, email us at support@innerify.co.

1. Who is responsible for your data

Smarthink LLC, a company incorporated in New Mexico (USA), located at 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110. Operates under the trade name Innerify.

For users residing in the European Union we process your data under the GDPR and cooperate with supervisory authorities when required.

Privacy contact: support@innerify.co.

2. What data we process

2.1. Data you provide

  • Name to personalize your reading.
  • Date, time and place of birth to calculate your Human Design chart. See §3.
  • Email to send you your chart, payment confirmations and service-related communications.
  • Password (if you create an account). Stored in irreversible hash (bcrypt via Supabase Auth). We cannot read it.
  • Payment data: handled directly by Stripe. We only receive the payment method token, the last 4 digits and the card brand.

2.2. Data collected automatically

  • Technical identifiers: IP address, User-Agent, language.
  • Analytics cookies (Google Analytics 4) — only if you accept the consent banner. See §7.
  • Minimal logs for security and abuse prevention (last logins, failed login attempts).

3. Special treatment of birth time

The combination of date + time + place of birth identifies a unique instant per person. As a precaution we treat it as a special category under GDPR (art. 9):

  • Legal basis: explicit consent that you give when submitting the test form.
  • Use: only to calculate your chart and store the result in your account. Never shared with advertisers or third parties other than the subprocessors listed in §5.
  • You can withdraw consent and delete your data at any time from Settings → Delete my account, or by emailing support@innerify.co.

4. Why we use your data and legal basis

PurposeLegal basis (GDPR)
Calculate your HD chart.Explicit consent (art. 9.2.a).
Provide the subscription service.Contract performance (art. 6.1.b).
Operational communications (welcome, price change, rebill warning).Contract performance.
Billing and tax compliance.Legal obligation (art. 6.1.c).
Usage analytics and service improvement.Consent (art. 6.1.a) — cookies.
Fraud prevention and security.Legitimate interest (art. 6.1.f).

5. Who we share your data with (subprocessors)

For the service to work, we rely on the following providers. All operate under data-processing agreements and adequate international transfer safeguards (SCCs / adequacy frameworks):

  • Supabase Inc. (USA / EU) — database, authentication and account storage.
  • Stripe Payments Europe, Ltd. (Ireland) — payment processing and subscription. PCI-DSS Level 1.
  • Resend, Inc. (USA) — transactional email delivery.
  • Vercel Inc. (USA) — web app hosting and CDN.
  • Human Design Hub — astronomical calculation of your chart. We only send date, time and place; not email or name.
  • OpenStreetMap / Nominatim — resolving your city of birth. We only send the text you type.
  • Google Analytics 4 (Google LLC, USA) — only if you accept the banner. Anonymized via Consent Mode v2.
  • Anthropic PBC (USA) — text generation for your HD reading. We never send your email or identifying data with the prompt.

We do not sell your data. Ever.

6. How long we keep your data

  • Active account: while your subscription is active or you keep the account open.
  • After account deletion: 6 months so you can reactivate without losing your chart. Then fully deleted.
  • Billing data: kept 6 years after the last transaction (tax obligation).
  • Cookie consent log: 13 months (to prove consent in case of audit).

7. Cookies and similar technologies

We only enable analytics and advertising cookies with your explicit consent through the banner. You can revoke it from Settings → Cookie preferences, or by deleting the innerify_consent cookie.

Strictly necessary cookies (session, security) are set without prior consent — they are essential for the site to work.

8. Your rights

You can exercise these rights at any time by emailing support@innerify.co (we reply within 30 days max):

  • Access your data.
  • Rectify incorrect data.
  • Erasure ("right to be forgotten").
  • Portability (export your chart as JSON from Settings).
  • Object and restrict processing.
  • Withdraw consent at any time.

You also have the right to file a complaint with your local supervisory authority (in Spain the AEPD: aepd.es).

9. Security

All connections are encrypted (TLS 1.2+). Passwords are hashed with bcrypt. The database applies Row-Level Security: each user can only access their own data. We audit access regularly.

In case of a data breach affecting your data, we will notify you within 72 hours together with the measures taken.

10. Minors

Innerify is not directed to minors under 16. If we detect an account of a minor without parental consent, we delete it.

11. Changes to this policy

If we update this policy significantly, we will notify you by email at least 30 days before it takes effect. Minor updates (typos, clarifications) take effect upon publishing.