Trust, Privacy and Security

Where groundpath keeps your data, who can see it, what we deliberately do not collect, and what we are not. Measured, dated, and stated plainly.

Data is held in Supabase's London region, in the United Kingdom — not in Australia. That is permitted under the Australian Privacy Principles, and it is stated plainly because most readers of an Australian mental-health site will assume otherwise.

Access is enforced by the database rather than the website. Every table carries row-level security, so a mistake in the site cannot release a record the database will not give up. Practitioner contact details, insurance details and emergency contacts are closed to signed-out visitors by both row policy and column grant. Registration numbers are deliberately open, because publishing them is what lets a client run their own check.

There is no session recording anywhere on the site, no advertising pixel, no analytics tag and no social widget. Errors are reported identified by account id only, with email addresses and phone numbers stripped before sending.

Card details are entered directly into Stripe and never reach groundpath. The Stripe script is not loaded on pages where nobody is paying.

groundpath holds no security certification and has had no external audit. It is not a crisis service, not a clinic, and does not employ the practitioners it lists.