Privacy notice

For wellbeingengine.io and the IWE developer sandbox. Last updated 13 August 2026.

The short version. If you sign up for sandbox keys we store your email address, a hashed version of your IP, and which browser and link brought you. We delete all of it 30 days after your key expires, automatically. The sandbox itself contains no real people - only synthetic test data we generated.

Who is responsible for your data

wellbeingengine.io is operated by All Toogether Ltd, a company registered in England and Wales (company number 14775309), whose registered office is Jactin House, 24 Hood Street, Manchester, United Kingdom, M4 6WX.

All Toogether Ltd is the data controller for personal data processed through this site. We are registered with the Information Commissioner's Office under registration number ZB544902.

What we collect, and why

There are two quite different things going on, and it matters which is which.

1. When you request sandbox keys

Calling POST /sandbox/signups, or using the button in our docs, stores:

WhatWhyBasis
The email address you supplyTo identify your sandbox client and contact you about the keyLegitimate interests - providing the sandbox you asked for
A hashed version of your IP addressRate limiting and abuse prevention. We store an HMAC, never the address itself, and cannot recover itLegitimate interests - keeping a free public service usable
Your browser user-agent and referring linkTo understand which channels and AI assistants send developers to usLegitimate interests

2. Inside the sandbox itself

Nothing about you, and nothing about anybody else. The sandbox runs against a synthetic workforce we generated - invented people, invented answers. Sandbox keys are deliberately not granted permission to create respondents, so no real person can be enrolled through them, and the engine has no free-text field to put personal data into.

If you later run the IWE on your own people, that is a separate deployment under a separate agreement, and your organisation is the controller for it.

How long we keep it

Sandbox keys expire 30 days after issue. A scheduled job then deletes the client record, and your email address is deleted with it. This is enforced by the database rather than by anyone remembering to do it.

Who we share it with

We do not sell or share your details. They sit with our infrastructure providers:

Your rights

You can ask for a copy of what we hold, ask us to correct or delete it, or object to our processing. Deletion is usually immediate - there is very little to remove, and it would have gone within 30 days anyway.

If you are not happy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies and local storage

This site does not use cookies, analytics, or any tracking technologies. We do not track visitors across sites, and we do not share data with advertising networks.

The interactive demo stores a single access key in your browser's local storage. This is strictly necessary for the demo to function, is first-party only, is never transmitted to third parties, and is not used for tracking or profiling. You can clear it at any time through your browser settings.

Contacting us

For data deletion requests, abuse reports, or questions about sandbox access, email hello@wellbeingengine.io.

We aim to respond to data protection requests within one month, as required by the UK GDPR.

Changes

If we change this notice we will update the date at the top.