Privacy and data choices

Your data should make sense too.

This page explains the privacy design for The Way In and Signal.OS in plain English. It separates what the current local candidate can record from what still needs owner, legal, provider, and exact-release proof.

The simple version

Collect less. Explain why. Prove the choice.

Email updates

Signup forms ask for an email address and sometimes an optional name. They record the update request, consent choice, time, and limited security information needed to protect the form.

Accounts and membership

The account system can hold identity, verification, session, membership, provider-standing, course, community, and entitlement state. Payment-card details are intended to stay with the payment provider, not this site.

Wellness and Signal.OS

The Signal Integrity Map and Signal.OS can involve wellness answers, derived results, profile context, and lab-like information. That deserves a separate, specific consent and retention boundary. Do not put personal health details in a public signup or community post.

Providers and community

Provider applications can include professional identity and standing information. Community use can include posts, votes, moderation, and course activity. Role, audience, access, removal, appeal, and retention must remain visible.

Anonymous site analytics

Anonymous site analytics run on thewayin.me unless you decline. A notice appears when you first arrive; if you decline there, or if your browser sends Do Not Track or Global Privacy Control, collection stops and stays stopped. You can change your mind at any time from Privacy choices in the footer.

AI-assisted features

Some Signal.OS features send specific content you provide, such as a question you ask or a document a coach is working with, to an outside AI processor to generate a response. That processor is contractually required not to retain the content or use it to train its models. It does not receive your name, email, or account identity along with that content. Nothing else on this site sends data to an AI processor.

Data map

What each lane is for

Data uses and how each lane works
LaneWhy it existsHow it works
Email requestSend the doctrine, reading updates, or private-prelaunch news the person asked for.Local code records a versioned request and subscription state, then returns an honest receipt. No sender or outbound confirmation delivery is connected or published. A working unsubscribe link delivered by email still needs exact proof.
Anonymous site analyticsMeasure page use and browser performance so the site can be improved.On unless you decline. Analytics may send page paths without query strings, referrer origin and path, a short-lived random identifier, device class, screen size, browser language, time, performance measurements, and allowlisted event labels to the SNRG-operated command service. Form values, account identity, email, wellness answers, and free-form text are excluded.
Account and securitySign in, verify control of an email, manage sessions, protect private areas, and respond to abuse.Used to verify your email, keep private areas private, manage sessions, sign out devices, and respond to abuse.
Courses and commerceShow access, record progress, fulfill purchases, handle refunds and disputes, and preserve provider economics.Order, webhook, entitlement, reversal, and course-progress controls are still being completed and tested.
Signal.OSProvide personalized research and education with source, uncertainty, safety, and next-actor context.The new candidate is held for independent safety review. No current public release claim is made.
Community and providersSupport role-labeled discussion, moderation, professional standing, course authorship, enforcement, and appeal.Local forum and standing controls exist in candidate form. Real staffing, operating rules, and provider relationships still need proof.
AI-assisted featuresGenerate a response to a specific question or document, such as the Signal.OS guide or a coach's document-reading tools.The specific content involved is sent to an outside AI processor under a contract that bars retaining it or training on it. Your name, email, and account identity are not included in that request. This lane covers only features that explicitly say they use AI; nothing else on this site works this way.
Your choices

The controls this system must make real

Say yes clearly

Email updates require a separate checkbox. The form returns a receipt showing whether your request was recorded. An email address without that choice is not a marketing subscription.

Change your mind

The local runtime includes one-step suppression and a visible unsubscribe state. No sender is connected or published yet. If sending is activated, every marketing email must provide a working unsubscribe path, and a successful suppression request must stop future marketing email without deleting security records needed to honor that choice.

See, correct, export, or delete

The target account experience includes authenticated requests, a status receipt, allowlisted export, correction, deletion review, and an explanation of anything that must be retained. Those workflows are not claimed live until their end-to-end tests pass.

Know who receives data

The final notice must name current service categories, purposes, locations, contracts, and retention. Provider wiring or a secret name is not proof of the current account, terms, or behavior.

Anonymous analytics, and how to decline

Analytics is on unless you decline it. Choosing no, using Do Not Track or Global Privacy Control, visiting from a preview or local address, or using a noncanonical hostname stops collection. Declining later works the same way: reopen Privacy choices in the footer and choose no. That removes the local analytics session identifier and blocks later sends from the page. Declining is honoured for as long as the choice is stored on this device.

Health privacy

HIPAA is not a slogan.

Whether HIPAA applies depends on the actual relationship among the platform, a provider, and the service being performed. A health app outside HIPAA may still face Federal Trade Commission privacy, security, and breach-notification duties. The final operating model needs qualified legal review of the exact data flows and provider relationships, not a badge placed on the site.

Official grounding reviewed for this candidate: HHS covered entities and business associates, FTC Health Breach Notification Rule guidance, and FTC email opt-out guidance.