MentalClarity
Data Security Statement
Last updated: September 12, 2026
We take appropriate technical and organisational measures to protect personal data, as required by GDPR Article 32.
1. Encryption
All traffic between your device and our servers is encrypted with TLS. Data at rest in our database and backups is encrypted by our hosting provider.
2. Access control
Accounts are protected by single-use magic sign-in links — there are no passwords to leak. Database access is restricted by row-level security so each account can only read its own results, and staff access to personal data is limited to what is strictly needed to run the service and support customers.
3. Payment data
Card data is entered directly into our payment provider's PCI-DSS certified payment fields and never touches our servers. We only store a payment reference, the amount, the currency and the subscription status.
4. Incident handling
We monitor errors and unusual activity. If a personal data breach is likely to result in a risk to your rights, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform affected users without undue delay.
5. Reporting a vulnerability
Email support@mentalclarity.me with the subject "Security". Please give us reasonable time to fix an issue before disclosing it publicly.