Security & Privacy
What we collect, what we show, and what we don't.
This page is maintained by Human Aligned Health to answer common security and privacy questions about the product. It states what is true today, in plain language, so an HR, IT, or legal reviewer can evaluate it without a conversation.
What we collect
- A participant's work email, used as the identifier to sign in with a magic link. No passwords are stored.
- The participant's self-report reading across the eight Thrivability dimensions, on a zero-to-ten scale.
- Anonymized usage events (page views, timing, which prompts were seen) used only to run and improve the product.
What we never collect
- No protected health information. Human Aligned Health is not a covered entity and does not operate inside HIPAA.
- No medical data of any kind - no diagnoses, medical records, insurance claims, biometrics, lab results, or health history.
- No genetic or family health information.
- No demographic profiling, no device or activity tracking, no free-text answers.
What the employer sees, and doesn't
- Individual readings are never visible to the employer. Not to HR, not to leadership, not through export.
- Aggregate views only render once at least twelve people have completed the reading for that Challenge. Below that number, no scores are shown to anyone but the participants themselves.
- The one identity-level fact the employer sees is participation status - whether an invited employee has taken the reading - so they can pace the Challenge. The employer does not see the reading itself.
- We do not sell individual answers. We do not share them with third parties. We do not train external models on them.
How data is protected
- Encrypted in transit (TLS) and encrypted at rest at the infrastructure layer.
- Passwordless sign-in by magic link - no password database exists to breach.
- Row-level access controls scope every read to the participant or the correct Challenge.
Deletion and data lifecycle
Any participant can request deletion of their individual reading at any time, without needing to go through their employer, by emailing support@humanalignedhealth.com.
When an employer ends their engagement, the aggregate is preserved as part of that Challenge's record; individual readings are deleted on request.
Regulatory posture
The Thriving Challenge is offered to employees directly and voluntarily, outside any group health plan. Participation does not affect health plan premiums, cost-sharing, or HSA/HRA contributions. Every purchasing employer attests to this when they buy.
Because we handle self-report wellbeing data and never touch medical information, we do not operate inside HIPAA and do not make clinical claims.
Certification-style claims (SOC 2, ISO 27001, GDPR, etc.) will be added only once the corresponding audits complete. We would rather be quiet and accurate here than loud and wrong.
For your reviewer
Two one-pagers you can hand to your IT, legal, or finance colleague without needing to loop us in.
Security & Compliance Summary
One page. What we collect, how it's protected, and what it is not.
Business Case Brief
One page. The claims-exposure framing and payback logic in plain numbers.
Both open directly. No form. No email required.
Contact
For anything not answered here, a signed DPA, or a deletion request: support@humanalignedhealth.com. A human replies.