home

privacy policy

This policy describes what What's Down actually collects and how that data is used, based on how the application works today.

Effective date: 6 August 2026

Who operates this

What's Down is operated by thedeeprussian. For privacy questions, access, correction, or deletion requests, email [email protected].

What we collect

  • Account identifier. When you use the app, we create an anonymous Firebase Authentication account. We store the Firebase user ID (UID). We do not require your name or email for the questionnaire.
  • Questionnaire selections. Your multiple-choice answers (stored as choice IDs).
  • Optional free text. If you leave an optional note, that text is stored and may be included in the prompt sent to the AI narrator.
  • Generated results. Deterministic scores, categories, summary fields (evidence, suggested actions, warnings), and related session metadata. The AI narrative is generated for your session response; we also store a narrator status (success, fallback, or failed) for operational measurement.
  • Timestamps and operational fields. Server-side created/completed times, session/diagnosis IDs, schema version, and basic metadata such as app version and that the session came from the web client.
  • Technical logs. Cloud Run writes structured operational logs. By design those logs use a hashed form of the user ID and do not include raw questionnaire answers, free-text notes, AI prompts, or AI response bodies. They may include session IDs and category identifiers needed to debug failures.

Why we use this information

  • To run the questionnaire and return a diagnosis result.
  • To store session history associated with your anonymous account (when persistence is enabled).
  • To measure aggregate usage and whether people return for another completed diagnosis (via operator tooling that reads Firestore; this is not exposed in the public app).
  • To debug failures, maintain security, and improve the application.

Service providers

Your data is processed by Google Cloud services used to run the product:

  • Firebase Authentication (anonymous accounts)
  • Cloud Firestore (session and diagnosis storage)
  • Cloud Run (API and frontend hosting)
  • Vertex AI / Gemini (AI narrative generation from diagnosis context and optional free text)
  • Cloud Logging (operational logs as described above)

Processing for the deployed environments is configured in the Google Cloud region europe-west1.

Advertising and sale of data

We do not sell your questionnaire content or diagnosis results. We do not use your answers for advertising. This product does not include Firebase Analytics, Google Analytics, advertising trackers, or a cookie-consent banner.

Retention

Completed diagnosis records are kept for up to 6 months after completion. After that, the operator deletes them using operational tooling. Deletion is operator-managed for this beta (not a continuously scheduled cloud job). For earlier deletion, email [email protected] with your account ID (see "Access, correction, and deletion" for how to find it). There is currently no self-service delete button in the app.

Access, correction, and deletion

To request access to, correction of, or deletion of data associated with your use of the service, email [email protected] and include your anonymous account ID (Firebase UID). We do not store an email address with anonymous accounts, and there is no self-service delete button. Without your account ID, we may not be able to find your records.

How to find your account ID (same browser and device where you used What's Down, before clearing site data):

  1. Open the What's Down site.
  2. Open your browser's developer tools (on many browsers: right-click → Inspect, or press F12 / Cmd+Option+I).
  3. Go to Application (Chrome/Edge) or Storage (Firefox/Safari).
  4. Under IndexedDB, open firebaseLocalStorageDb (the name may vary slightly).
  5. Open the stored Firebase auth entry (often a key starting with firebase:authUser:).
  6. In the JSON, copy the "uid" value and include it in your email.

If you cleared site data, used a different browser or device, or the auth entry is missing, we may be unable to locate prior records.

Security

We rely on Google Cloud defaults and standard practices for the services listed above. No system is perfectly secure. We do not claim specific certifications, encryption guarantees beyond what those platforms provide, or absolute protection against unauthorized access.

Children and minors

Minors may use What's Down. The service is a self-reflection tool, not therapy or medical care. If you are a parent or guardian and have concerns, contact [email protected].

Anonymity

Questionnaire use is tied to an anonymous Firebase UID stored with your diagnosis records. That is not the same as having no identifier. Clearing site data or using another device/browser typically creates a new anonymous account, which breaks continuity with prior history.

Changes

We may update this policy as the product changes. The effective date at the top will be updated when we do. Continued use after an update means the revised policy applies to new activity.

This page is about privacy and data handling. For medical/therapy limits, see the disclaimer.