Legal

Data Policy

Effective date: July 13, 2026

Last updated: July 13, 2026

This Data Policy describes the categories of data we handle, where and how it is stored, how it is protected, and how you can have it deleted.

1. Data categories

  • Identity data: name, email, organization, role/title.
  • Authentication data: hashed passwords, session tokens, OAuth identifiers (e.g., Google).
  • Assessment data: your answers, computed scores, and any notes.
  • Usage data: pages viewed, actions taken, timestamps, IP address, user agent.
  • Billing data: purchase history and Stripe customer identifiers. Card numbers are handled by Stripe, not by us.

2. Where data is stored

Application data is stored in a managed Postgres database hosted on infrastructure operated by our hosting provider in the United States. See our Subprocessors list for details.

3. How data is protected

  • In transit: TLS 1.2+ for all connections.
  • At rest: AES-256 encryption for the database and backups.
  • Access controls: role-based access; production access limited to personnel who need it; multi-factor authentication required.
  • Row-level security: database-level policies restrict each user to their own records; team/org admins see only their team's records.
  • Backups: automated daily backups with limited retention.

4. Data minimization

We collect only what we need to run the assessment, produce results, and operate the business. We do not ask for demographic categories we do not use.

5. Aggregation and anonymization

To generate benchmarks (team-vs-team, sport-average, division-average), we compute aggregates from many users. Aggregated statistics do not identify individuals and may be retained after your account is deleted.

6. Retention

We retain personal data for the life of your account. On deletion request, we remove personal data within 30 days from live systems and within 90 days from backups. Legal, tax, and fraud-prevention records may be retained longer as required by law.

7. Deletion requests

Email info@jenfrytalks.com from the address on your account. Team members should also copy their team administrator, who owns the team's data.

8. Data portability

On request, we will provide your personal data in a common, machine-readable format (JSON or CSV).

9. Incident response

If we become aware of a security incident affecting your data, we will notify you and, where required, regulators, within the timeframes required by applicable law.

Contact us

JenFryTalks LLC
Baltimore, Maryland, USA
info@jenfrytalks.com

This document is a plain-English template drafted by the product team. It is not legal advice. Please have qualified counsel review it before relying on it for regulated use (schools, EU/UK customers, enterprise contracts, or disputes).