Privacy notice
Version 0.1 · Draft · Effective date to be set
This page covers the somaforming.com website and the application form on it. It is deliberately short, because the form deliberately collects very little.
1. What the application form collects
Exactly these fields, and nothing else:
| Field | Why |
|---|---|
| Name | To address you |
| Age | Cohort 01 has an age range; out of range we keep you on the list for cohort 02 |
| To reply to you | |
| Whether you wear a sleep tracker, and which | The protocol requires nightly ring data |
| Caffeine, cups per day | The probe is caffeine; habitual intake changes the interpretation |
| Shift work or timezone crossings | An exclusion criterion in the protocol |
| Whether you have a practitioner who would act on the result | The personal arm is chosen with them |
| The one question you want answered | It is what we read first |
| Website or LinkedIn (optional) | Context |
Alongside those, the form records technical context: the campaign link identifier if you arrived through one, UTM parameters, the referring page, when the page loaded, and a coarse browser family such as "mac" or "ios". Your IP address is not stored; it is hashed and used only to limit how many applications can be sent from one place in ten minutes, and the hash cannot be turned back into an address.
What the form deliberately does not collect
No medications, no BMI, no STOP-BANG score, no sleep duration, no diagnoses.
Those are health data. They belong on the physician-facing intake after the screening call, behind consent and a real clinical relationship — not on a public web page. The screening criteria that use them are published openly at /protocol/ so you can rule yourself out before ever telling us anything.
2. Where it goes
- A Google Sheet, which is how we read and triage applications.
- Email — a notification to us, and an automatic acknowledgement to you, sent through Resend.
- If either of those fails, the application is written to Cloudflare Workers KV for up to 90 days so it can be re-sent by hand. This exists so that a technical fault never loses your application.
We do not sell it, we do not share it with advertisers, and we carry no advertising.
3. Analytics and session recording
We use PostHog to understand how the page is read and where the form loses people, and Cloudflare Web Analytics as a simple second counter.
PostHog session replay is enabled. All form inputs are masked — the recording shows that a field was filled, not what was typed — and the free-text question is explicitly marked as private so its contents are never captured. Analytics requests are proxied through somaforming.com rather than sent to a third-party domain.
If you submit an application, your email address is used as your identifier in PostHog so that the application can be connected to the visit that produced it.
4. How long we keep it
- Applications: kept for the duration of cohort 01 and for 24 months afterwards, so we can contact you about cohort 02 if you asked us to.
- The failure fallback copy: 90 days, then deleted automatically.
- Rate-limit hashes: 10 minutes.
- Analytics: PostHog's default retention for this project.
5. Cookies and local storage
The site stores the campaign link identifier and UTM parameters in your browser's local storage so that an application can be attributed to the message that brought you here. PostHog sets its own cookies for session continuity. There is no advertising cookie and no cross-site tracking pixel.
6. How to get your data deleted
Write to apply@somaforming.com and ask. We will delete your application row, the email thread, and your PostHog person profile, and confirm when it is done. You do not need to give a reason.
7. Who to contact
Version 0.1 (privacy) · Draft for counsel · Cosmist Bio, Inc.