1. Who we are
Netwell (“Netwell,” “we,” “us”) operates an AI job-displacement risk assessment platform and is developing an income protection product for workers whose roles may be disrupted by artificial intelligence. This Privacy Policy explains what personal data we collect when you use our website and services, how we use it, and the rights you have over it.
For the purposes of the UK GDPR, EU GDPR and California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Netwell is the “data controller” / “business” responsible for your personal data.
2. Data we collect
We only collect information you provide to us directly or that is generated while you use our services. Specifically:
2.1 Assessment data
When you complete the AI risk assessment, we collect:
- Your full name
- Your email address
- Your phone number (optional)
- Your job title and industry
- The occupation your job title matched, if it matched one — its standard code, its published title, and its category. This is what lets us use task-level data about that occupation rather than a generic baseline.
- Every answer you give in the assessment, and which set of questions you were asked. Which questions those are depends on the path you pick at the start (employed, student, job seeker, career changer, or founder/freelancer). They cover things like your career level, how you are employed, the mix of tasks in your work, how routine or judgment-led it is, how much you use AI tools, what you are working toward, and how much time you have. Some of your answers affect your score and some are stored only so we can see what we asked you.
- Your age range
- Your educational background — the highest level you have completed
- Financial information you choose to give: the band your annual income falls in, roughly what you save in a month, and how long you could cover essentials if your income stopped. The last of these is what your financial-resilience score is calculated from. Every one of them offers “Prefer not to say”, and choosing it stores no figure.
- Your city / state / province location, searched via OpenStreetMap. Required since 2026-08-20. Location is approximate — we store the place you select, not your precise device location.
- A computed AI-displacement risk score (0–100) and tier (low, medium, high, critical) derived from your answers
- Whether you agreed to let us use your data to help improve career research. This box starts ticked. It is optional and you can untick it before you submit, or withdraw later using the controls at the end of this policy. Your score does not depend on it either way.
- Referral source (where you arrived from, if known)
- Submission timestamp
If you took an earlier version of this assessment, we may also hold answers it asked and the current one does not — company size, salary band, months of savings, recent headcount changes in your team, and how concerned you were. We no longer ask for these.
If you choose to import a résumé or LinkedIn export to pre-fill your assessment, the file is read in memory to extract the fields shown on the confirmation screen, and then discarded. We do not store the file or its text — only the fields you confirm and submit are saved, as part of the list above.
2.2 Whitepaper request data
When you download our whitepaper, we collect your name, email, and optionally your company and role, along with your marketing preferences.
2.3 Technical data
When you submit an assessment or join a waitlist, we store your IP address alongside that submission, together with the approximate city, region, country, and approximate latitude and longitude our hosting provider derives from it. We use this to understand where demand comes from and to detect abuse. These coordinates are network-level estimates produced from the IP address — typically accurate only to a city — and are not device GPS: we never ask your browser for its location, and we do not use invasive fingerprinting.
Our hosting and analytics providers additionally process standard technical information such as device type, browser, referrer URL, and pages viewed.
Anonymous step counts. We count how many visits reach each step of the assessment each day, so we can see where people stop. Each count is only a date, the step, which path was chosen, and the name of the link you arrived on, if any (for example “newsletter”). No name, email, IP address, cookie, or device identifier is stored with it, so it cannot be linked back to you. The counts stay in our own database and are shared with no one.
2.4 Payment data
When you buy from us, payment is handled by our payment processor, Stripe. Your card details are entered on Stripe’s hosted checkout and never touch our servers. Every purchase is a one-time payment — Dashboard Access, the AI Career Audit and career strategy sessions — and for each we store the record of what you bought: your billing email, your Stripe customer identifier, which product it was, the amount, the status, and the Stripe session identifier. We never store card numbers, expiry dates or security codes.
If you bought a membership before 23 August 2026, when Netwell still sold monthly and annual plans, we also still hold that record: the Stripe subscription identifier, its status, and when its billing period ended. Nothing on the site sells a subscription any more, and nothing renews.
2.5 Waitlist and alert signups
If you join a waitlist (risk alerts, or a Netwell Fund), we store the name, email address, and any company or role you enter, plus the technical data in Section 2.3. We use it only to contact you about the thing you asked to hear about.
2.6 Accounts we create for you
Submitting an assessment or joining a waitlist creates a Netwell account for that email address automatically. We do this so your results are yours — reachable by a sign-in link, and deletable by you — rather than sitting in our database with no way for you to reach them. You can delete the account and everything attached to it at any time (Section 9), and you are never charged for having one.
2.7 Cookies and local storage
We use a small number, and no advertising or cross-site trackers:
- Sign-in cookies (
sb-*, set by Supabase): strictly necessary — they are what keeps you signed in. Set when you sign in, and refreshed as you browse. - Local storage (
nw_*keys): your monthly check-in answers and saved plan preferences. These stay in your browser and are not transmitted to us.
2.8 What we do not collect
We do not collect financial account numbers ourselves — we never receive your full card number; payments are handled by Stripe as described in Section 2.4. We do not collect government identifiers, biometric data, or information about your health, sexual orientation, religion, politics, or protected class status. We do not purchase data about you from third parties.
2.9 Follow-up notes
When you finish the assessment, a copy of your results email goes to our team inbox, without your sign-in link. If we follow up with you, we may keep a short note with your email address, such as the date we wrote to you. This note is deleted with your account, included when you export your data, and removed after 24 months without an update.
3. How we use your data
We use personal data for the following purposes:
- Delivering the assessment — computing your risk score, generating your personalized results, and emailing you a copy
- Product development — aggregating anonymized assessment data to understand displacement patterns and shape the Netwell product
- Communicating with you — sending you your results, the whitepaper, launch announcements (only if you opted in), and replying to your questions
- Protecting the service — detecting abuse, rate limiting, and maintaining security
- Legal compliance — meeting our obligations under applicable law
3a. Where we use AI, and where we do not
An AI does not decide your score. The score is worked out by a fixed formula that we can show you line by line. A language model is used in two places, and neither one sets a number.
- Putting your plan into plainer words — the Career outlook summary and each step. Every figure stays exactly as the formula set it.
- Reading a resume you choose to import — it fills in your job title and industry, which you check on screen before we score anything. The file itself is discarded and never stored.
Both are optional. If the model is unavailable, the product falls back to rules-written text and the assessment is unaffected.
4. Legal basis for processing (UK / EU users)
If you are in the United Kingdom or European Economic Area, we rely on:
- Consent (Art. 6(1)(a) GDPR) — when you opt in to early-access notifications, marketing emails, or optional questionnaire items. You can withdraw consent at any time.
One exception, stated plainly: the “help improve career research” box on the last step starts ticked. A pre-ticked box is not a “clear affirmative action” under Art. 4(11), so we do not present it as GDPR consent. If you are in the UK or EEA and would rather we did not use your data that way, untick it before submitting, or withdraw at the end of this policy and we will stop. - Performance of a contract (Art. 6(1)(b)) — to provide the assessment you requested and deliver results
- Legitimate interests (Art. 6(1)(f)) — to analyze aggregated trends, improve the service, and build our product. Your interests and rights are balanced against ours; you may object (see Section 7).
- Legal obligation (Art. 6(1)(c)) — where we must process data to comply with applicable law
5. Who we share data with
We do not sell your personal data. We share it with a small set of trusted service providers (“sub-processors”) that help us run the product:
- Supabase, Inc. — database and authentication (hosted on AWS, primarily in the United States)
- Vercel Inc. — web hosting and content delivery
- Resend (Drop, Inc.) — transactional email delivery
- Google LLC (Google Workspace) — our team mailbox. A copy of the results email we send you, without your sign-in link, goes to this mailbox so our team can follow up
- Stripe, Inc. — payment processing for subscriptions. Card details are entered on Stripe’s hosted checkout and never touch our servers.
- Anthropic, PBC — optional AI-generated career narrative and résumé parsing. Assessment-derived profile data and résumé text are processed only to generate your results and are not used to train models.
- Product analytics — none in use. Netwell runs no third-party analytics or advertising scripts today, so there is no such processor to name. (The anonymous step counts in Section 2.3 are kept in our own database and shared with no one.) If that changes we will ask before anything loads, and list the provider here first
- OpenStreetMap Foundation (Nominatim) — geocoding the location text you type so we can show matching place suggestions. Only the search term is sent; no account or contact details are shared.
- Cloudflare, Inc. — bot protection (Turnstile) on public forms, when enabled. Your IP address and a challenge token are sent to Cloudflare to verify the submission is human.
- Upstash, Inc. — rate limiting for public endpoints, when enabled. Rate-limit keys derived from your IP address — a truncated SHA-256 hash, not the address itself — are stored for the length of the limit window, which is ten minutes on most endpoints and up to an hour on account deletion.
Each sub-processor is contractually required to protect your data to the same standards we do. We may also disclose data to regulators or law enforcement if required by law, or to a successor entity in connection with a merger or acquisition. In any such event we would update this policy and notify you where required.
6. International transfers
Our sub-processors are primarily based in the United States. When personal data is transferred from the UK/EEA to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. Copies are available on request.
7. Your rights under GDPR (UK / EU users)
You have the right to:
- Access a copy of the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Restrict how we process your data
- Object to processing based on legitimate interests, including for direct marketing
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a supervisory authority (in the UK, the ICO; in the EU, your national data protection authority)
To exercise any of these rights, email hello@fromthegroundup.ai. We will respond within 30 days.
Your copy of your data
Everything we hold about your account, as a file you can open or keep. It includes your assessments, your score history and your billing records.
8. Your rights under CCPA / CPRA (California residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and retain
- Delete personal information we collected from you
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information — we do not sell or share personal information in the CCPA/CPRA sense, so there is nothing to opt out of, but we make this explicit nonetheless
- Limit the use of sensitive personal information — we do not collect sensitive personal information as defined by CPRA
- Non-discrimination — we will not discriminate against you for exercising any of these rights
To exercise these rights, email hello@fromthegroundup.ai with “California Privacy Request” in the subject line. We will verify your identity before acting on the request.
9. Retention and deletion
We retain assessment and whitepaper request data for up to 24 months from submission, after which it is either deleted or irreversibly anonymized for research purposes. If you create an account with us, we retain account data for as long as your account is active and for a reasonable period thereafter to meet legal or operational requirements.
Your data, your call — delete anytime. Sign in and use delete anytime at the bottom of your dashboard sidebar. Deletion is immediate and irreversible: your assessments, score history, saved plans, waitlist entries, follow-up notes, and login are removed on the spot, and your billing row is stripped of personal identifiers.
We keep the payment records our payment processor and tax law require (Stripe remains the system of record for transactions); those contain your billing details, not your assessment answers. If you would rather we did it for you, email hello@fromthegroundup.ai from the address on your account and we will action it within 30 days.
10. Security
We use industry-standard security measures including TLS in transit, encrypted storage at rest, row-level security on our database, and least-privilege service credentials. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and any required authorities without undue delay, as required by applicable law.
11. Children
Netwell is intended for working-age adults and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced on our website and, where required, by email. The “effective” date at the top of this page reflects the most recent version.
13. Contact us
For any privacy question, email hello@fromthegroundup.ai. For general correspondence, email hello@fromthegroundup.ai.