Privacy

Last updated: 7 August 2026

This page describes what we collect, why, for how long, and what you can do about it. It is written to match what the software actually does.

Who is responsible

The operator of I Ask Field is the controller of your personal data. Contact: privacy@iaskfield.com.

What we collect

Account: your name, email address, password (stored only as a salted hash, never in readable form), and chosen language.

Your question (focus): the text you write when you order or join the pilot.

Your practice: the two daily numbers you record (clarity, steadiness), the optional note, and anything you write in your journal.

Your reports: the text prepared for you by a person.

Technical: a session identifier in a cookie. We do not use advertising or analytics trackers.

What we deliberately do not collect

No photograph. No phone number. No date, time or place of birth. No precise location. No payment card data — payments are handled outside this application.

These fields were considered and removed because we could not justify them against the purpose.

Why we are allowed to hold it

To deliver what you asked for: performance of the agreement between us.

For your practice and journal: your explicit consent, which you can withdraw at any time.

For marketing messages: a separate consent, never bundled with the one above.

How long we keep it

Account and reports: while your account exists, then deleted within 30 days of deletion.

Practice and journal entries: same as the account.

Audit records: 12 months. They contain who did what and when, never the content itself.

Your rights

Access and portability: Settings → Export my data gives you everything we hold, as a file.

Erasure: Settings → Delete my account removes your data permanently.

Rectification, restriction and objection: write to privacy@iaskfield.com.

You may also complain to your national data protection authority.

Who else sees your data

The person preparing your report sees your question and your report. Nobody else on the team reads your journal.

Our hosting provider stores the data in the European Union. We do not sell or share your data with anyone.

Security

Passwords are hashed with scrypt. Sessions are stored as hashes, so a copy of the database cannot be used to impersonate you. All traffic is encrypted in transit.