Email updates
Signup forms ask for an email address and sometimes an optional name. They record the update request, consent choice, time, and limited security information needed to protect the form.
This page explains the privacy design for The Way In and Signal.OS in plain English. It separates what the current local candidate can record from what still needs owner, legal, provider, and exact-release proof.
Signup forms ask for an email address and sometimes an optional name. They record the update request, consent choice, time, and limited security information needed to protect the form.
The account system can hold identity, verification, session, membership, provider-standing, course, community, and entitlement state. Payment-card details are intended to stay with the payment provider, not this site.
The Signal Integrity Map and Signal.OS can involve wellness answers, derived results, profile context, and lab-like information. That deserves a separate, specific consent and retention boundary. Do not put personal health details in a public signup or community post.
Provider applications can include professional identity and standing information. Community use can include posts, votes, moderation, and course activity. Role, audience, access, removal, appeal, and retention must remain visible.
Anonymous site analytics run on thewayin.me unless you decline. A notice appears when you first arrive; if you decline there, or if your browser sends Do Not Track or Global Privacy Control, collection stops and stays stopped. You can change your mind at any time from Privacy choices in the footer.
Some Signal.OS features send specific content you provide, such as a question you ask or a document a coach is working with, to an outside AI processor to generate a response. That processor is contractually required not to retain the content or use it to train its models. It does not receive your name, email, or account identity along with that content. Nothing else on this site sends data to an AI processor.
| Lane | Why it exists | How it works |
|---|---|---|
| Email request | Send the doctrine, reading updates, or private-prelaunch news the person asked for. | Local code records a versioned request and subscription state, then returns an honest receipt. No sender or outbound confirmation delivery is connected or published. A working unsubscribe link delivered by email still needs exact proof. |
| Anonymous site analytics | Measure page use and browser performance so the site can be improved. | On unless you decline. Analytics may send page paths without query strings, referrer origin and path, a short-lived random identifier, device class, screen size, browser language, time, performance measurements, and allowlisted event labels to the SNRG-operated command service. Form values, account identity, email, wellness answers, and free-form text are excluded. |
| Account and security | Sign in, verify control of an email, manage sessions, protect private areas, and respond to abuse. | Used to verify your email, keep private areas private, manage sessions, sign out devices, and respond to abuse. |
| Courses and commerce | Show access, record progress, fulfill purchases, handle refunds and disputes, and preserve provider economics. | Order, webhook, entitlement, reversal, and course-progress controls are still being completed and tested. |
| Signal.OS | Provide personalized research and education with source, uncertainty, safety, and next-actor context. | The new candidate is held for independent safety review. No current public release claim is made. |
| Community and providers | Support role-labeled discussion, moderation, professional standing, course authorship, enforcement, and appeal. | Local forum and standing controls exist in candidate form. Real staffing, operating rules, and provider relationships still need proof. |
| AI-assisted features | Generate a response to a specific question or document, such as the Signal.OS guide or a coach's document-reading tools. | The specific content involved is sent to an outside AI processor under a contract that bars retaining it or training on it. Your name, email, and account identity are not included in that request. This lane covers only features that explicitly say they use AI; nothing else on this site works this way. |
Email updates require a separate checkbox. The form returns a receipt showing whether your request was recorded. An email address without that choice is not a marketing subscription.
The local runtime includes one-step suppression and a visible unsubscribe state. No sender is connected or published yet. If sending is activated, every marketing email must provide a working unsubscribe path, and a successful suppression request must stop future marketing email without deleting security records needed to honor that choice.
The target account experience includes authenticated requests, a status receipt, allowlisted export, correction, deletion review, and an explanation of anything that must be retained. Those workflows are not claimed live until their end-to-end tests pass.
The final notice must name current service categories, purposes, locations, contracts, and retention. Provider wiring or a secret name is not proof of the current account, terms, or behavior.
Analytics is on unless you decline it. Choosing no, using Do Not Track or Global Privacy Control, visiting from a preview or local address, or using a noncanonical hostname stops collection. Declining later works the same way: reopen Privacy choices in the footer and choose no. That removes the local analytics session identifier and blocks later sends from the page. Declining is honoured for as long as the choice is stored on this device.
Whether HIPAA applies depends on the actual relationship among the platform, a provider, and the service being performed. A health app outside HIPAA may still face Federal Trade Commission privacy, security, and breach-notification duties. The final operating model needs qualified legal review of the exact data flows and provider relationships, not a badge placed on the site.
Official grounding reviewed for this candidate: HHS covered entities and business associates, FTC Health Breach Notification Rule guidance, and FTC email opt-out guidance.