Skip to content

Legal

Privacy Policy

What this website collects, why, and what we do not do. It is a short list, because this site collects very little.

The short version

This site has no analytics, no advertising pixels, no tracking scripts and no third-party cookies. We do not sell or share your personal information, and we never have. The fonts are served from our own servers rather than from a font network, so loading a page does not tell anyone else that you visited.

The only personal information we collect from visitors is what you type into the contact form and send to us.

Who this policy covers

This policy covers wildlyprimal.com. It does not cover our Instagram profile, which is governed by Meta’s privacy policy, or any laboratory, supplier or scheduling service you may deal with separately.

It also does not cover the information you give us once you become a client. That is handled under the intake and privacy terms you receive when the engagement begins, which are more protective than this page because the information is more sensitive.

What we collect

When you submit the contact form, we receive what you chose to enter:

  • Your name
  • Your email address
  • Which service you are interested in, if you selected one
  • The message you wrote

What our hosting provider records

Like every website, ours runs on servers that keep operational logs. Our host, Vercel, records standard request data (IP address, browser and device type, the page requested, referring page and a timestamp) for delivery, security and abuse prevention.

We do not use these logs to build a profile of you, we do not combine them with contact-form submissions, and we do not have a way to identify you from them.

What we do not collect

We want to be specific rather than vague, because “we may collect” language in privacy policies usually means “we do”. On this site we do not:

  • Run Google Analytics or any other analytics product
  • Run advertising pixels from Meta, Google, TikTok or anyone else
  • Set cookies on visitors’ browsers
  • Load fonts, scripts or images from third-party networks
  • Use session recording, heatmaps or scroll tracking
  • Buy or receive personal information about you from data brokers
  • Collect health information through this website

Why we use what we collect

We use contact-form submissions to read your inquiry, reply to it, and (if we go on to work together) to set up that engagement. That is the whole purpose.

We use server logs to keep the site available and to deal with abuse. Where a legal basis is required, ours is our legitimate interest in operating a secure website, and, for your inquiry, taking steps at your request before entering into a contract.

Who else sees it

We do not sell, rent, trade or share your personal information for anyone’s marketing. A small number of service providers process it on our behalf, under contract, only to provide their service to us:

  • Vercel: hosts the site and runs the contact form endpoint
  • Resend: delivers the contact-form email to our inbox
  • Google (Gmail): the inbox that receives and stores our email
  • GitHub: stores the site’s content and images, which the site is built from

We may also disclose information if the law requires it, or where it is necessary to establish or defend a legal claim, or to protect someone’s safety.

Cookies

This site sets no cookies on visitors’ browsers. There is no cookie banner because there is nothing to consent to.

One cookie exists on the site, and only administrators of the practice ever receive it: a sign-in cookie for the private content-management area at /admin. It is strictly necessary for signing in, holds only a signed session token, expires after eight hours, and is marked HttpOnly, Secure and SameSite=Strict. Visitors never receive it.

How long we keep it

Contact-form emails stay in our inbox so we have a record of the conversation. We review them periodically and delete inquiries that did not become an engagement, and in any case we will delete yours sooner on request.

Server logs are retained by our host on their standard schedule, which is a matter of days to a few weeks, and then rotated out. Administrator account records exist for as long as that person administers the site.

How we protect it

The whole site is served over HTTPS. The contact form is validated and rate-limited on the server, and the credentials for our email provider never reach your browser.

Administrator passwords are stored only as salted scrypt hashes, never in readable form. Sessions are signed, short-lived and compared in constant time.

No system is perfectly secure, and we will not claim otherwise. What we can say is that this site holds very little worth stealing, by design.

Health information

Health coaching, as we practice it, is generally not a HIPAA-covered service; we do not bill health insurance and we are not a covered entity or a business associate. That means the health information you send us is not protected by HIPAA, which is exactly why we ask you not to send it through this website.

Please keep your contact-form message to what you would like to discuss. Symptoms, diagnoses, medications and lab results belong in the secure intake process, not in an email.

If you have already sent us health details through the form and would like them removed, email us and we will delete the message.

Your rights

Depending on where you live (including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and a growing number of other states), you have rights over the personal information a business holds about you. We extend the following to every visitor, regardless of state, because drawing lines by geography seemed worse than simply honoring them:

  • Know what personal information we hold about you and why
  • Get a copy of it in a portable form
  • Correct anything inaccurate
  • Delete it
  • Opt out of sale, sharing or targeted advertising, although we do none of these, so there is nothing to opt out of
  • Not be discriminated against for exercising any of these rights

To exercise any of them, email us from the address you contacted us with, or tell us enough to find your message. We will respond within 45 days, and will tell you if we need longer. If we decline a request, we will say why, and you may appeal by replying to that response.

Do Not Track and Global Privacy Control

We do not track visitors across sites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honor them by construction rather than by configuration.

Children

This site is not directed to children, and our services are for adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has sent us information through the contact form, email us and we will delete it.

Visitors outside the United States

Our practice is in Florida and our service providers are in the United States. If you contact us from outside the country, your information will be processed in the United States, where privacy laws differ from those where you live.

We are not currently offering services outside the United States. If you are in the European Economic Area or the United Kingdom and would like your inquiry deleted, email us and we will do it.

Changes to this policy

If we change this policy we will update the date at the top of the page. If a change materially affects how we handle information already collected, we will make a reasonable effort to notify the people affected directly.

Contact

Privacy questions and requests go to the email address below. A person reads them.

Wildly Primal

Jacksonville Beach, Florida

wildlyprimal@gmail.com

This page is provided for transparency about how we operate. It is not legal advice, and it does not create rights or obligations beyond those the law already gives you.