Pre-launch notice. This privacy policy is a working draft. We are having it reviewed by legal counsel before we take material traffic. If you rely on it, please contact us first.

Legal

Privacy Policy

Effective April 14, 2026

1. Who we are

Netwell (“Netwell,” “we,” “us”) operates an AI job-displacement risk assessment platform and is developing an income protection product for workers whose roles may be disrupted by artificial intelligence. This Privacy Policy explains what personal data we collect when you use our website and services, how we use it, and the rights you have over it.

For the purposes of the UK GDPR, EU GDPR and California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Netwell is the “data controller” / “business” responsible for your personal data.

2. Data we collect

We only collect information you provide to us directly or that is generated while you use our services. Specifically:

2.1 Assessment data

When you complete the AI risk assessment, we collect:

  • Your full name
  • Your email address
  • Your phone number (optional)
  • Your job title, industry, company size, and salary band
  • Your self-reported answers on AI adoption in your team, recent headcount changes, months of savings, and concern level
  • Demographic details you provide: your age range, educational background, and a city / state / province location (searched via OpenStreetMap). Location is approximate — we store the place you select, not your precise device location.
  • A computed AI-displacement risk score (0–100) and tier (low, medium, high, critical) derived from your answers
  • Whether you opted in to early-access notifications
  • Referral source (where you arrived from, if known)
  • Submission timestamp
  • If you choose to import a résumé to pre-fill your assessment, the text content of the file you upload

2.2 Whitepaper request data

When you download our whitepaper, we collect your name, email, and optionally your company and role, along with your marketing preferences.

2.3 Technical data

Our hosting and analytics providers may process standard technical information including your IP address, device type, browser, referrer URL, and pages viewed. We do not collect precise geolocation or use invasive fingerprinting.

2.4 Payment data

If you subscribe to a paid plan, payment is handled by our payment processor, Stripe. Your card details are entered on Stripe’s hosted checkout and never touch our servers. We store only your subscription status, billing email, and Stripe customer identifier.

2.5 What we do not collect

We do not collect financial account numbers ourselves — we never receive your full card number; payments are handled by Stripe as described in Section 2.4. We do not collect government identifiers, biometric data, or information about your health, sexual orientation, religion, politics, or protected class status. We do not purchase data about you from third parties.

3. How we use your data

We use personal data for the following purposes:

  • Delivering the assessment — computing your risk score, generating your personalized results, and emailing you a copy
  • Product development — aggregating anonymized assessment data to understand displacement patterns and shape the Netwell product
  • Communicating with you — sending you your results, the whitepaper, launch announcements (only if you opted in), and replying to your questions
  • Protecting the service — detecting abuse, rate limiting, and maintaining security
  • Legal compliance — meeting our obligations under applicable law

4. Legal basis for processing (UK / EU users)

If you are in the United Kingdom or European Economic Area, we rely on:

  • Consent (Art. 6(1)(a) GDPR) — when you opt in to early-access notifications, marketing emails, or optional questionnaire items. You can withdraw consent at any time.
  • Performance of a contract (Art. 6(1)(b)) — to provide the assessment you requested and deliver results
  • Legitimate interests (Art. 6(1)(f)) — to analyze aggregated trends, improve the service, and build our product. Your interests and rights are balanced against ours; you may object (see Section 7).
  • Legal obligation (Art. 6(1)(c)) — where we must process data to comply with applicable law

5. Who we share data with

We do not sell your personal data. We share it with a small set of trusted service providers (“sub-processors”) that help us run the product:

  • Supabase, Inc. — database and authentication (hosted on AWS, primarily in the United States)
  • Vercel Inc. — web hosting and content delivery
  • Resend (Drop, Inc.) — transactional email delivery
  • Stripe, Inc. — payment processing for paid subscriptions. Card details are entered on Stripe’s hosted checkout and never touch our servers.
  • Anthropic, PBC — optional AI-generated career narrative and résumé parsing. Assessment-derived profile data and résumé text are processed only to generate your results and are not used to train models.
  • PostHog, Inc. — product analytics (only if enabled in your region)
  • OpenStreetMap Foundation (Nominatim) — geocoding the location text you type so we can show matching place suggestions. Only the search term is sent; no account or contact details are shared.

Each sub-processor is contractually required to protect your data to the same standards we do. We may also disclose data to regulators or law enforcement if required by law, or to a successor entity in connection with a merger or acquisition. In any such event we would update this policy and notify you where required.

6. International transfers

Our sub-processors are primarily based in the United States. When personal data is transferred from the UK/EEA to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. Copies are available on request.

7. Your rights under GDPR (UK / EU users)

You have the right to:

  • Access a copy of the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”)
  • Restrict how we process your data
  • Object to processing based on legitimate interests, including for direct marketing
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent
  • Lodge a complaint with a supervisory authority (in the UK, the ICO; in the EU, your national data protection authority)

To exercise any of these rights, email privacy@netwell.ai. We will respond within 30 days.

8. Your rights under CCPA / CPRA (California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and retain
  • Delete personal information we collected from you
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of your personal information — we do not sell or share personal information in the CCPA/CPRA sense, so there is nothing to opt out of, but we make this explicit nonetheless
  • Limit the use of sensitive personal information — we do not collect sensitive personal information as defined by CPRA
  • Non-discrimination — we will not discriminate against you for exercising any of these rights

To exercise these rights, email privacy@netwell.ai with “California Privacy Request” in the subject line. We will verify your identity before acting on the request.

9. Retention and deletion

We retain assessment and whitepaper request data for up to 24 months from submission, after which it is either deleted or irreversibly anonymized for research purposes. If you create an account with us, we retain account data for as long as your account is active and for a reasonable period thereafter to meet legal or operational requirements.

Your data, your call — delete anytime. Email privacy@netwell.ai from the email address on your account and we will delete your assessment, account, and email records within 30 days.

10. Security

We use industry-standard security measures including TLS in transit, encrypted storage at rest, row-level security on our database, and least-privilege service credentials. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and any required authorities without undue delay, as required by applicable law.

11. Children

Netwell is intended for working-age adults and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced on our website and, where required, by email. The “effective” date at the top of this page reflects the most recent version.

13. Contact us

For any privacy question, email privacy@netwell.ai. For general correspondence, email hello@netwell.ai.

See also our Terms of Service.