AndHeal™
Privacy Policy & Disclaimer
Last Updated: April 2026
We collect and process personal information to deliver structured insight into leadership performance and biological capacity. Because this information includes health-adjacent, lifestyle, and biological data, we hold it to a higher standard of transparency than a typical website privacy policy requires.
AndHeal™ (“we,” “our,” or “us”) is a biology-informed leadership performance platform. We provide education, structured insight, and strategic wellness guidance. We do not provide medical diagnosis or treatment. This distinction is central to how we collect, process, and protect your information. This Privacy Policy explains how information is handled when you visit andheal.com, use our AndHeal Signal Index™, communicate with us, or engage our services.
1. Information We Collect
Website Information
When you visit andheal.com, we collect information you voluntarily provide, including your name, email address, phone number, and any messages or inquiries submitted through forms, chat, or email.
We may also automatically collect limited technical data such as IP address, browser type, pages visited, and time spent on the site. This information helps us improve website functionality and user experience.
AndHeal Signal Index™ Data
When you complete the AndHeal Signal Index™, you provide substantially more detailed information. This includes:
- Personal details: name, email, age, gender, current role, organization type, and leadership scope
- Biological and lifestyle inputs: responses about energy patterns, stress history, sleep quality, digestive function, cognitive performance, hormonal experience, and nervous system regulation
- Investment and readiness responses: professional cost assessment, investment history, future vision, and readiness to engage
- Open-text responses: detailed written answers describing your personal experience in your own words
This assessment data is health-adjacent and personally sensitive. It is collected exclusively to generate your personalized biological profile report and to support the educational guidance provided through AndHeal.
AndHeal is not a healthcare provider and is not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). The information collected through this assessment is not medical records. It is collected and processed for educational and performance analysis purposes only. Certain categories of assessment data may qualify as sensitive personal data under applicable state privacy law, and we obtain your explicit consent before collecting and processing this information.
2. How Your Data Is Processed and Stored
Your assessment data is processed and stored across several separate platforms, each with a distinct purpose. This separation is intentional and exists to protect the sensitivity of your information.
Airtable — Raw Assessment Responses
- Stores your complete assessment responses, including all open-text answers
- Data is encrypted in transit (TLS) and at rest
- Hosted on servers in the United States
- SOC 2 Type II certified (independently audited security controls)
- Accessible only by AndHeal through secure API credentials
This is the only platform that stores your full open-text responses. These responses contain the most personally sensitive information in the assessment and are stored separately from your contact record for this reason.
FluentCRM — Contact and Profile Data
- Stores structured contact information: name, email, age, gender, role, and organization type
- Stores your assigned profile name, domain score percentages, and assessment completion data
- Does not store your open-text responses or raw assessment answers
- Hosted on AndHeal’s own WordPress server at Bluehost — your contact data does not leave AndHeal’s hosting infrastructure
- Used to deliver your report via email and to manage communication preferences
Anthropic API — Report Generation
- Your assessment responses are transmitted securely to Anthropic’s AI system to generate your personalized biological profile report
- Anthropic does not use API inputs to train their models
- Anthropic retains API inputs and outputs for up to 7 days for safety monitoring purposes, after which they are automatically deleted
- Your data passes through Anthropic’s system temporarily during report generation and is not stored permanently
PDFShift — PDF Report Conversion
Upon completion of the AndHeal Signal Index™, your report is automatically converted to PDF format using PDFShift, a third-party HTML-to-PDF conversion service. PDFShift generates the PDF and writes it directly to AndHeal’s own storage infrastructure. PDFShift does not retain a copy of your report
PDFShift processes your report data only during conversion and does not store your report content at any point. Your report bypasses PDFShift’s storage entirely
PDFShift is HIPAA compliant and GDPR compliant. Their privacy policy is available at pdfshift.io/legal/privacy
PDF report generation is automatic and is covered by the consent you provide before beginning the assessment. No separate consent is required at the time of generation
AWS S3 — PDF Report Storage
Stores your completed AndHeal Signal Index™ report as a PDF file
The PDF filename contains no personally identifying information and cannot be used to identify you without cross-referencing AndHeal’s internal records
Data is encrypted in transit (TLS) and at rest (AES-256)
Hosted on Amazon Web Services (AWS) servers in the United States
Accessible only by AndHeal through secure AWS credentials
Your completed report is the only data stored in S3. Your raw assessment responses, open-text answers, and contact information are not stored in S3 and remain in Airtable and FluentCRM as described above
No assessment data is stored on the web hosting platform (Bluehost) that serves the assessment application. The application code is hosted there; your data is not.
All data collected through the AndHeal Signal Index™ is processed and stored in the United States.
3. AI-Generated Report
Your AndHeal Signal Index™ report is generated using artificial intelligence. The AI system reads your specific assessment responses, applies AndHeal’s proprietary scoring methodology, and produces a personalized narrative report that reflects your individual biological patterns.
This report is designed to deliver educational insight based on the AndHeal framework. It is not a medical diagnosis, clinical assessment, or treatment recommendation. The AI system operates under strict guidelines that reflect AndHeal’s methodology and Donna O’Connor’s biology-informed approach.
The quality and personalization of the report is directly shaped by the honesty and specificity of your responses.
The AI-generated report is based entirely on your self-reported data. AndHeal does not guarantee the accuracy, completeness, or applicability of the report’s output to your individual circumstances. The report is an educational tool, not a verified analysis, and should not be relied upon as a substitute for professional medical or clinical evaluation.
4. How We Use Your Information
Your information is used for the following purposes:
- Generating your personalized biological profile report
- Preparing for and delivering your Initial Plan of Action session
- Communicating with you about your assessment results and educational guidance
- Scheduling and delivering services
- Providing educational content through AndHeal’s programs
- Improving our assessment instrument and service delivery
- Sending updates or information you have opted into
We do not sell, rent, or share your personal information for marketing purposes. We do not sell personal data, and we do not use personal data for targeted advertising.
If you are participating in an AndHeal program through a corporate engagement, your organization’s service agreement with AndHeal may include additional data use terms that apply to your participation. Those terms are described in the corporate Participant Data Notice provided to you prior to your assessment.
5. Access to Your Information
Your assessment responses, scoring data, and assigned profile are reviewed by AndHeal’s practitioner team to support session preparation and educational guidance delivery. This review ensures that the personalized recommendations in your Plan of Actions accurately reflect your individual biological context.
A practitioner notification is sent to [email protected] upon assessment completion. This notification includes your scoring summary and selected open-text responses to enable informed session preparation.
Your information is not shared with external parties for marketing, research, or any purpose beyond delivering the services described in this policy.
6. Data Retention
- Airtable: Your assessment responses are retained for ongoing service delivery, program continuity, and to support future sessions. You may request deletion at any time.
- FluentCRM: Your contact record and profile data are retained for communication and service delivery unless you opt out or request deletion.
- Anthropic: Your data is processed temporarily for report generation only and is automatically deleted within 7 days.
AWS S3: Your completed report PDF is retained for ongoing service delivery and your future access. You may request deletion at any time.
If you request deletion of your data, we will remove your records from Airtable, FluentCRM, and AWS S3 within 30 days of your request, except where retention is required for legal, regulatory, or legitimate operational purposes. Anthropic’s temporary processing data is automatically purged within their 7-day retention window. PDFShift does not retain report data at any point; no deletion action is required for PDFShift.
7. Saved Progress and Partial Responses
The assessment includes an optional save-and-resume feature. If you choose to save your progress at the midpoint of the assessment, you will be asked to provide your email address. A unique resume link will be sent to you so you can return and complete the assessment from where you left off.
When you use this feature, your partial responses and the screen you reached are stored in Airtable along with your email address and a timestamp. This data is used to enable your return to the assessment and, if you do not return within 48 hours, may be used by AndHeal for follow-up outreach to invite you to complete the assessment.
Your browser may also store your progress locally using standard browser storage. This data remains on your device only and is not transmitted to any external system.
8. Consent to Data Processing
Before beginning the AndHeal Signal Index™, you will be asked to acknowledge that you understand and consent to the following:
- Your responses will be collected and stored as described in this policy
- Your responses will be processed using an AI system to generate your personalized report, which will be automatically generated as a PDF and stored securely within AndHeal’s own infrastructure using a third-party conversion service that does not retain your data
- A copy of your completed report will be received and reviewed by AndHeal’s practitioner team for session preparation
- Your report will be delivered automatically by email to the address you provide, and your contact information will be used for ongoing communications from AndHeal, which you can opt out of at any time
This acknowledgment is required to proceed with the assessment. Certain assessment data may constitute sensitive personal data under the Texas Data Privacy and Security Act or comparable state laws. Your consent satisfies the requirement for prior consent to process such data. You may withdraw your consent at any time by contacting us, and you may request deletion of your data as described in Section 6.
9. Cookies and Tracking Technologies
We may use cookies or similar technologies to improve site performance, understand visitor behavior, and enhance user experience. You may disable cookies through your browser settings at any time.
10. Third-Party Services
We use trusted third-party providers to operate our website, deliver our assessment, and manage communications. These providers include hosting platforms, data storage services, AI processing systems, scheduling tools, email services, and analytics tools. Each provider is required to safeguard your information and use it only as necessary to provide their services.
The specific platforms used for assessment data processing are described in Section 2 of this policy. Each third-party provider operates under its own privacy policy and terms of service. AndHeal is not responsible for the independent data practices of these providers beyond the scope of services they perform on our behalf.
11. Data Security
We take reasonable administrative and technical measures to protect your information. Assessment data is encrypted in transit and at rest. Access to your data is restricted to authorized personnel only. While no online platform can guarantee absolute security, we design our systems to safeguard your data against unauthorized access, misuse, or disclosure.
In the event of a data breach that affects your personal information, AndHeal will notify affected individuals and relevant authorities in accordance with applicable law.
12. Your Rights and Choices
You may:
- Request access to your personal information
- Request corrections or updates to your data
- Request deletion of your information from our systems
- Request a copy of your personal data in a portable format
- Opt out of communications at any time
- Withdraw consent for data processing
Requests can be made by contacting us using the information in Section 15.
13. Children’s Privacy
AndHeal does not knowingly collect personal information from children under the age of 13. The AndHeal Signal Index™ is designed for adults in leadership and professional roles. If information from a child is identified, it will be removed promptly.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our services, technology, or legal requirements. Updates will be posted on this page with a revised effective date. If changes are material, we will notify you through the email address associated with your account.
15. Contact Information
If you have questions or concerns about this Privacy Policy or about how your data is handled, please contact:
AndHeal™
Email: [email protected]
Phone: 832-707-2879
Website: andheal.com
Disclaimer
Educational and Non-Clinical Services
AndHeal provides educational and informational services only. We provide biology-informed education, structured insight, and strategic wellness guidance. We do not diagnose, treat, cure, or prevent any medical condition. AndHeal is not a healthcare provider, and our services do not create a provider-patient relationship.
Donna O’Connor is not acting as a licensed healthcare provider in the context of AndHeal engagements. Her background in biology, nursing, and functional medicine informs the AndHeal methodology, which is delivered as an educational framework.
Assessment and Report
The AndHeal Signal Index™ is an educational instrument designed to help you see your own biological patterns with greater precision. Your personalized report is generated using artificial intelligence that applies AndHeal’s proprietary methodology to your specific responses. The report provides educational insight and structured awareness. It is not a medical assessment, clinical evaluation, or diagnostic tool.
The domain scores, profile assignment, and narrative in your report reflect patterns identified through your self-reported responses. They are not clinical measurements. Individual experiences vary, and the assessment does not account for all variables that may affect your health or performance.
Guidance and Recommendations
Any guidance, recommendations, or Plan of Actions provided through AndHeal’s programs are educational suggestions based on established functional medicine and nutritional science principles. They are not prescriptions. They are not a substitute for professional medical advice, diagnosis, or treatment.
Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition. If you experience unexpected or adverse symptoms after beginning any recommended input, discontinue it and consult your physician.
No Professional Relationship
Your use of AndHeal’s services, including the AndHeal Signal Index™ and any resulting report or guidance, does not create a provider-patient, advisory, fiduciary, or consulting relationship between you and AndHeal or any of its practitioners. The information and educational content provided through AndHeal is not a substitute for independent professional judgment or advice. You are solely responsible for how you interpret and act upon the information provided.
Limitation of Liability
To the fullest extent permitted by law, AndHeal, its founder, practitioners, and affiliates shall not be liable for any indirect, incidental, consequential, special, or punitive damages arising from or related to your use of our services, including the AndHeal Signal Index™ and any AI-generated report. This limitation applies regardless of the theory of liability, whether in contract, tort, strict liability, or otherwise.
In no event shall AndHeal’s total aggregate liability to you for all claims arising from or related to our services exceed the total amount you have paid to AndHeal for the specific Service giving rise to the claim during the twelve (12) months preceding the event, or one hundred dollars ($100), whichever is greater.
Participation in AndHeal programs is voluntary and undertaken at your own risk. Outcomes vary based on individual biology, choices, and circumstances. AndHeal is not responsible for any decisions you make based on the information provided through our services.
Governing Law
This Privacy Policy, Disclaimer, and any disputes arising from or related to your use of AndHeal’s services shall be governed by and construed in accordance with the laws of the State of Texas, without regard to its conflict of law principles. Any legal action or proceeding arising under this policy shall be brought exclusively in the courts located in Harris County, Texas, and you consent to the jurisdiction of such courts.
Acknowledgment
By using this website, completing the AndHeal Signal Index™, or engaging AndHeal’s services, you acknowledge that you have read and understood this Privacy Policy and Disclaimer, and you agree to the collection, processing, and use of your information as described herein.
