Legal
Consumer Health Data Privacy Policy
Effective September 29, 2026 · Contact: emil@epasini.com
Don't Panic is a training and coaching platform, not a medical provider. Some of what you tell us can still say something about your physical or mental health. This policy explains exactly what that information is, what we do with it, and your rights over it. It is written to meet Washington's My Health My Data Act, Nevada's and Connecticut's consumer health data laws, and the equivalent rules in Canada and Europe. Our full Privacy Policy covers everything else.
1. THE HEALTH DATA WE COLLECT
- Check-In answers: your self-ratings in the app (for example sleep, energy, emotions, temptations and how regulated you feel), and the scores built from them.
- Program activity: which practices and modules you complete. On its own this is not health data, but next to your Check-In it can suggest something about your wellbeing, so we treat it the same way.
- Private plans: if you are a coaching client, the training or recovery plan written for you, which can reflect an injury or condition you told us about.
- Proximity application and intake answers: what you choose to tell us about your physical state, injuries, sleep, nutrition, mental health history, medications, supplements and substance use.
- What you post in The Room: anything you choose to share there about yourself.
2. WHERE IT COMES FROM
Directly from you, and only from you. We do not buy health data, we do not receive it from doctors or insurers, and we do not infer it from tracking you around the web (we don't do that, ever).
3. WHY WE COLLECT IT AND HOW WE USE IT
- To show you your own Check-In history and progress in the app.
- For Proximity clients: to decide whether the work is a fit and to design your coaching.
- To keep your account and the Platform working and secure.
That's it. We never use health data for advertising, never sell it, and never use it to decide anything about you outside the service you asked for.
4. YOUR CONSENT
We collect health data only when you give it to us to use a feature you asked for: taking the Check-In, applying for Proximity, or completing the intake. The intake form asks for your explicit consent before you submit it. You can withdraw consent at any time by deleting your account or emailing us, and we will stop collecting and delete what we hold.
5. WHO WE SHARE IT WITH
Only with the service providers that store and deliver it on our behalf, under contract:
- Supabase: stores Check-In answers, program activity and private plans
- Formspree: delivers application and intake forms to us
- Cloudflare: hosts the Platform
- Daily: carries live video sessions, which may include what you say on a call
We do not share health data with any other third party or affiliate, and we do not sell it. If the law ever required us to disclose it (for example under a court order), we would disclose only what was required.
6. YOUR RIGHTS
- Confirm and access: ask whether we hold health data about you, get a copy, and get the list of the providers above.
- Delete: delete your account yourself (Profile, then Delete account), which erases your Check-In answers, activity, plan and posts immediately, or email us to delete application and intake answers.
- Withdraw consent at any time.
- Appeal: if we decline a request, reply to our answer and ask us to reconsider. If you are still unhappy, you can contact your state Attorney General or your privacy regulator.
Send any request to emil@epasini.com. We respond within 30 days (45 at most where the law allows), and we will never charge you or treat you differently for asking.
7. SECURITY AND RETENTION
Health data is encrypted in transit and access is locked to your own account and to the founder. Check-In answers and plans are kept while your account exists. Application and intake answers are kept for the length of any engagement and up to 12 months after, then deleted.
8. CONTACT
Privacy Officer: Emil Pasini · Email: emil@epasini.com · or use the contact form · Location: Ontario, Canada