Privacy Standards for AlexZah Self-Guided Tools
A narrow, testable promise for specifically named fixed-choice browser tools.
Answers stay in the current page session.
In a qualifying AlexZah self-guided tool, your selected answers and generated result exist only in the page's JavaScript memory while you use the tool. The tool does not put them in cookies, browser storage, the URL, analytics events, form submissions, or server requests.
The webpage still makes ordinary requests needed to load. Consented analytics may record only the public tool identifier and three aggregate lifecycle events: start, complete, and CTA click. Those events must never include choices, scores, inferred states, generated text, or other answer-derived values.
This standard applies only when a tool displays the No-answer-storage standard badge and is listed on this page. It does not cover paid apps, forms, checkout, accounts, consent cookies, ordinary server or CDN logs, external websites, browser extensions, device sync, clipboard history, or screenshots.
What stays only in this browser tab
- Fixed choices selected during the current session.
- Temporary step and focus state.
- Results assembled from fixed public templates.
- Visible result text copied after an explicit action.
Refreshing or leaving the page clears this state because the tool does not persist it. The result cannot be recovered by AlexZah later.
What qualifying tools never ask you to submit
A qualifying tool uses fixed buttons or predefined controls. It does not ask you to type a private situation, memory, symptom, message, craving, task, relationship detail, or journal entry. It does not create a psychological profile or risk score.
If a future tool genuinely requires free text, it does not qualify for this badge. It needs a separate privacy, safety, data-flow, and retention review.
What we never put in storage, analytics, or requests
Browser and URL storage
No answer state in cookies, localStorage, sessionStorage, IndexedDB, Cache Storage, service-worker persistence, URL paths, query strings, fragments, or history state.
Requests and forms
No answer state in fetch, XMLHttpRequest, sendBeacon, WebSocket, forms, image-query pixels, navigation parameters, API requests, or hidden fields.
Analytics payloads
No choices, branch IDs, scores, categories, profiles, generated text, copied text, support-route use, or inferred product fit.
Logs and replay
No answer state in console, error, debug, or session-replay logs. Qualifying tool areas are checked for third-party capture before publication.
The three aggregate events we may record
tool_start
Recorded once when a visitor deliberately begins.
tool_complete
Recorded once when a useful result is displayed.
tool_cta_click
Recorded when an ordinary, non-safety action is selected.
Only a stable public tool identifier and current public page path may accompany these events when required by the site's aggregate analytics setup. Consent choices, blockers, or unavailable analytics may prevent an event from being sent.
What ordinary website infrastructure still receives
The page still loads HTML, styles, JavaScript, fonts, images, consent infrastructure, and linked pages. Hosting and CDN logs may receive the requested public path, timestamp, IP address, and user agent. Consented analytics may receive approved aggregate events. The promise is that tool answers stay separate from those requests—not that the web page has no network activity.
Clipboard behavior is local and explicit
- Copy occurs only after a visitor presses a copy control.
- Only the visible generated result is copied; hidden metadata is excluded.
- Copied content and answer paths are not sent to analytics.
- A local status message confirms success or gives a clear fallback.
- Operating systems, clipboard managers, extensions, and other apps may retain clipboard history outside AlexZah's control.
Safety exits do not become conversion moments
A qualifying tool lets a visitor stop without completing it and keeps practical safety guidance separate from promotion. A safety panel does not record which answer opened it, does not emit a lifecycle event, and contains no product, booking, contact, or promotional action.
Every tool also explains its educational scope, that it cannot assess a person or replace professional or crisis support, that no outcome is guaranteed, and that it can be stopped at any time.
How every tool is tested
- Source scan. We search the tool HTML and JavaScript for storage APIs, cookies, URL mutation, forms, network methods, analytics payloads, debug logging, and third-party widgets.
- Event allowlist. We verify the three event names, permitted public fields, CTA URLs, and the absence of answer-derived attributes.
- Every branch. Isolated Playwright runs each flow without touching a visitor's browser session.
- Storage inspection. Cookies, local storage, session storage, IndexedDB, Cache Storage, URL, and history are inspected before, during, after completion, after copy, after reset, and after refresh.
- Network inspection. Request URLs, bodies, and analytics objects are checked for answer terms or branch data.
- Safety route. The stop/support path is tested separately for zero lifecycle events and zero promotional actions.
- Interaction quality. Keyboard order, visible focus, reduced motion, sampled contrast, reset and stop behavior, and 44×44-pixel targets are checked.
- Responsive review. Full screenshots and overflow checks run at 320, 375, 390, 768, 1024, 1280, and 1440 pixels.
Tools currently covered by this standard
Therapy Consultation Question Builder
Fixed choices, in-memory result generation, local copy action, and aggregate-only lifecycle events. The current audit found no answer storage or answer-bearing request.
Open the question builderWhat this standard does not cover
- Paid AlexZah apps, which may use local storage, accounts or licences, and different analytics.
- Contact, booking, checkout, email, account, or support forms.
- The site's consent manager, cookies, or general analytics policy.
- External sites, including NerveWindow tools reached through a link.
- The optional free-text field on the current Do I Need Therapy? check-in, which is described separately and does not receive this badge.
The current Terms of Service and site policies govern their own surfaces. This technical standard is not legal advice, a certification, or a claim of universal compliance.
Common questions
Are my tool answers stored?
Not in a qualifying badged tool. Answer state exists in the page's JavaScript memory and disappears when you refresh or leave the page.
Does the tool use analytics?
It may record start, complete, and CTA click with a public tool identifier and path only. Choices, results, scores, generated text, and inferred states are excluded.
Does nothing leave my device?
That would be too broad. The webpage still loads HTML, styles, scripts, fonts, and images, and normal server or CDN metadata may be created. Consented analytics may receive approved aggregate events. Tool answers are kept out of those requests.
Can I save my result?
Where a copy button is offered, you can copy the visible result locally. AlexZah does not retain a recoverable copy. Your device, clipboard manager, browser extensions, screenshots, or synced clipboard may behave differently.
Why not save progress?
Qualifying tools are intentionally short enough to finish in one session. Avoiding persistence reduces sensitivity and complexity.
Does this standard apply to paid apps or forms?
No. Paid apps, contact and booking forms, checkouts, email, account and support flows have their own policies and data behavior.
Sources and principles
- European Data Protection Board: Privacy by design and by default.
- EDPB Guidelines 4/2019 on Article 25.
- UK Information Commissioner's Office: Data minimisation.
- Federal Trade Commission: Privacy by design for mobile apps.
This standard follows data-minimisation and privacy-by-design principles. It does not claim regulatory certification.
Standard version 1.0 · Published August 2026 · Coverage changes only after a fresh dated audit