Personal context. Personal control.
What stays here
What we store
This page describes the first version of GroundState: account sign-in, the free PrePrompt readiness assessment, local DNA and bloodwork file validation, optional Strava and Oura connections, device-support notification requests, and Stripe test checkout.
Your readiness score
Your score and local file summaries stay in this browser’s storage until you remove them or sign out. We don’t send them to our server or include them in analytics. An active wearable connection can count toward your score again when you return.
The assessment lets you select files for local checking or connect a supported wearable. File contents are not sent to GroundState. A wearable connection stores recent summaries with your account, as described below.
Your local files
When you select a raw DNA file or bloodwork report, GroundState reads and validates it inside your browser. Scans and photos use an English OCR model loaded from GroundState and run on your device. The source file, variant rows, genotypes, laboratory values, and extracted or OCR text are not sent to our server or saved in browser storage. This browser stores only a summary, such as the local filename, size, detected format, record counts, and recognized marker names, until you clear it or sign out.
When you select a personality result or personal-notes file in the assessment, GroundState checks only its filename, type, and size. It does not read, upload, store, or analyze the file contents. The filename and size stay in this browser until you remove the file or sign out.
If you preview a Bluesky or GitHub public profile, your browser requests public profile information directly from that provider. The provider receives the request and may see your IP address. GroundState does not receive or store the profile URL or returned content. The preview stays in browser memory and clears when you reload or close the page; it does not establish that you own the profile.
Your Strava connection
If you choose to connect Strava, Strava asks you to approve read-only access to your activities. GroundState stores your Strava athlete identifier, granted permissions, sync times, encrypted access credentials, and the latest 30 activity summaries. A summary can include its name, activity type, date, distance, moving time, elevation, and average heart rate when Strava provides it. We do not request permission to create or change Strava activities.
Syncing sends a request from GroundState’s server to Strava. Disconnecting asks Strava to revoke the access token and deletes the imported activity summaries and connection from GroundState. Local deletion does not depend on Strava’s response.
Your Oura connection
If you choose to connect Oura, Oura asks you to approve access to daily summaries. GroundState stores the granted permission, sync times, encrypted access credentials, and up to 30 days of sleep, readiness, and activity scores, step counts, and active calories. We do not request your email, personal profile, raw heart-rate series, tags, sessions, SpO2, or workout details.
Syncing sends requests from GroundState’s server to Oura. Disconnecting asks Oura to revoke access and deletes the connection and every imported Oura summary from GroundState. Local deletion does not depend on Oura’s response.
Device-support notifications
If you request an update for WHOOP, COROS, or Apple Health, we store your account ID and chosen device. We use your account email to send one notification if that direct connection becomes available. You can cancel a request from the device dialog on the assessment page; deleting your account also deletes the request. Requesting an update does not connect or import data from that device.
Sample briefs
The public examples use invented records. Selections and edits stay in page memory and clear when you reload or leave. Copying uses your clipboard; downloading saves the visible text as Markdown. Neither action sends it to an AI or saves it to your account. Preparing a reusable brief from your own records is not yet available.
File-based brief notifications
If you request an update when file-based briefs are ready, we store your account ID, request date, and any optional problem selections and free-text feedback you submit. We use your account email for that single update. Do not include health details or file contents in feedback. No brief text, file details, or score are added automatically. Cancel from the notification dialog on your brief next-step page at any time; deleting your account also deletes the request.
Your account
We store the email address and account information needed to sign you in, linked provider identifiers and authentication tokens where required, email verification records, and sessions. Google or Apple may also provide your name and profile image when you use those providers.
A necessary, HttpOnly cookie identifies your session. Signing out ends that session. Email sign-in links expire after 15 minutes and work once.
Stripe test checkout
When test checkout is enabled, Stripe processes test payment details on its hosted page. We store your account ID, selected package, test amount and currency, Stripe Checkout and Payment Intent identifiers, and payment status. GroundState does not receive or store card numbers. Test payments move no real money and create no entitlement or fulfillment.
Email and sign-in providers
Requesting a sign-in link sends your email address to our configured email delivery service. Choosing Google or Apple takes you to that provider, which processes the sign-in under its own privacy terms.
We limit repeated email requests using short-lived counters keyed by a protected hash of the address. These counters contain no assessment answers.
Hosting and operational records
The production setup is planned to use Vercel for the application and Supabase PostgreSQL for account records. Hosting, payment, delivery, and connected-service providers may process technical request information, such as IP addresses, as part of operating the service. Marketing analytics remain disabled unless explicitly enabled. When enabled, our self-hosted Umami service measures only the public landing page and primary assessment CTA clicks; it does not run on sign-in, assessment, results, file, wearable, or checkout routes, and it receives no account, health, genetic, file, or assessment data.
What comes later
Clinical and genetic interpretation, encrypted vault storage, AI ID profile creation, other personal-data processing, and additional device connections are planned capabilities. Their storage and privacy details will be explained before those features become available.
Start with the assessment