Parachute | Tether | Tandem Privacy and Consumer Health Data Policy

Combined web and mobile policy

Operator: Nickelsense Inc.
Applies to: Parachute, Tether, and Tandem websites at https://myparachute.live, https://mytether.live, and https://mytandem.live, Parachute, Tether, and Tandem for iOS, Parachute, Tether, and Tandem for Android, and related services
Effective: October 2, 2026
Last updated: October 2, 2026
Version: 1.0

This policy is a notice. It is not a substitute for a separate consent, authorization, cookie choice, research consent, or AI-training consent where the law requires one. Each of those choices is presented to you separately.


Table of contents

Part I — The short version

  1. Summary you can read in a minute
  2. Scope, roles, and who operates what
  3. Health-law status: HIPAA and 42 C.F.R. Part 2

Part II — What we collect and why

  1. Information we collect
  2. Product-specific information (Parachute, Tether, Tandem)
  3. Why we use information
  4. How we separate your data
  5. Mobile app and device permissions

Part III — Tracking technologies

  1. Cookies, SDKs, and similar technologies
  2. Sensitive surfaces where trackers are prohibited
  3. Recording, session replay, and video

Part IV — Optional programs, each separately consented

  1. Optional product analytics
  2. Optional recovery research
  3. Optional AI/ML model training
  4. How AI features process your information

Part V — Disclosure, retention, and safety

  1. When we disclose information
  2. Retention and deletion
  3. Safety and legal disclosures
  4. Security
  5. Breach notification

Part VI — Your rights

  1. Consumer health data notice
  2. Your rights and how to exercise them
  3. Children
  4. International use
  5. Changes to this policy
  6. Contact and complaints

Annexes
A. California notice at collection
C. Consent inventory (which choice controls what)


Part I — The short version

1. Summary you can read in a minute

Parachute | Tether | Tandem is a peer-support and information service operated by Nickelsense Inc.. It is not medical care and it is not an emergency service.

Recovery status, substance-use focus, mental-health focus, meeting attendance, check-in scores, and even the fact that you use this app are highly sensitive. We treat them as consumer health data whether or not a specific law requires it.

In plain terms:

2. Scope, roles, and who operates what

This policy applies to https://myparachute.live, https://mytether.live, and https://mytandem.live, the Parachute, Tether, and Tandem iOS app, the Parachute, Tether, and Tandem Android app, and the related consumer Service operated by:

Nickelsense Inc.
Louisville, Kentucky
privacy@nickelsense.com
Settings → Privacy (in the App or on the web)

Sponsored or white-label installations. If you use a separately branded installation sponsored by an employer, provider, treatment center, or other organization, review that deployment's specific notice. Nickelsense and the sponsoring organization may hold different controller, business, or processor roles depending on who determines each purpose and means of processing. For the Parachute, Tether, and Tandem services described in this policy, Nickelsense Inc. decides how and why your information is processed. For a sponsored or white-label installation, the roles of Nickelsense and the sponsoring organization are stated in that installation's own notice and in our contract with the sponsor.

What this policy does not cover. It does not cover an external provider, meeting, fellowship, facility, employer, payment app, app store, AI provider's own consumer services, or any site you reach through a link. Those parties have their own policies.

3. Health-law status: HIPAA and 42 C.F.R. Part 2

HIPAA. The direct-to-consumer Service generally is not offered by a HIPAA covered entity, and Nickelsense generally is not acting as a HIPAA business associate for information you enter directly into the consumer Service. That means information you enter here may not receive HIPAA protection. A particular sponsored installation or health-system integration may be different and will provide additional notice.

42 C.F.R. Part 2. Nickelsense is not a "part 2 program" merely because members discuss substance-use recovery. Information you provide directly to the consumer Service may not receive Part 2 protection. If a Part 2 program transmits records into a sponsored installation, additional restrictions and notices apply.

What does protect this data. State consumer health data laws — including the Washington My Health My Data Act and Nevada SB 370 — state comprehensive privacy laws, the FTC Act, the FTC Health Breach Notification Rule, and our own contractual and technical commitments in this policy.


Part II — What we collect and why

4. Information we collect

CategoryExamplesWhere it comes from
Account and contactEmail, optional phone, password hash, name or display name, city/state/ZIP, age representationYou
Consumer health and recoveryRecovery status and stage, primary and secondary substance focus, sobriety or recovery date (optional), mental-health focus, support-relationship type, wellbeing and check-in scores, self-assessment answers and safety flag, sponsor and recovery-plan statusYou; generated from your use
Sensitive profile fieldsGender identity, sex at birth, race or ethnicity, religion, education, military status, profile visibility choicesYou (all optional)
ContentPosts, comments, reactions, group material, public shares, reviews, uploads, creator materials, profile imageYou
Private contentDirect messages, journals and notebook entriesYou
AI dataPrompts, conversation content, voice input and output, model output, safety classification, provider and model metadataYou; AI provider
Support and meeting activitySupport requests, availability, connections, meeting RSVPs and attendance, live-session routing and quality metadataYou; generated
CommercePlan, purchase record, gift recipient email, transaction identifier, payment status, app-store or Stripe metadata. Not your full card numberYou; payment and app-store providers
Specialist and creatorCertification documents, claimed credentials, listings, moderation and review recordsYou; issuing or public sources where checked
Device and networkIP address, device, app, and browser type, operating system, language, access time, push token, cookie and local-storage identifiers, crash and security logsYour device; service providers
LocationCity, state, ZIP, and precise or approximate device location, only if you turn on location in the mobile App to find nearby meetingsYou; your device with permission
Contacts matchingSHA-256 hashes generated on your device from phone numbers, an opted-in member's own hash, and match resultsYour device; members
Moderation, safety, and legalReports, actions taken, appeals, evidence, blocked users, legal requests, preservation recordsYou; other users; authorities
InferencesRecovery-stage band, risk or resource-display flag, recommendations, matching and ranking signals, aggregate metricsGenerated by us

On tokens and hashes: replacing a direct identifier with a hash or token is pseudonymization, not anonymization, for as long as a link or a reasonable method of re-identification exists. We do not describe pseudonymous data as anonymous.

5. Product-specific information

5.1 Parachute

Parachute may collect your addiction or recovery focus, recovery stage, an optional sobriety date, sponsor status, recovery-plan status, support requests, meeting engagement, recovery resources viewed, and — if you opt in — recovery research data.

5.2 Tether

Tether may collect the type and duration of your support relationship, supporter burnout and readiness questionnaire scores, resources you use, gifts you send, and — if you opt in — research data.

Do not enter the supported person's health or recovery information without that person's permission unless law permits it. Tether does not give you access to another person's account or records.

5.3 Tandem

Tandem may collect your mental-wellness focus, wellbeing and check-in responses, support requests, community engagement, and — if you opt in — research data. Tandem does not create a clinical record.

6. Why we use information

PurposeCategories usedBasis or your choice
Create and secure your accountAccount, device and security, age representationProviding the Service you requested; security
Deliver the features you chooseContent, health and recovery, profile, meetings, support, location where you chose itProviding the Service; consumer-health consent where required
Apply your privacy and audience choicesIdentity, profile, content, connectionsProviding the Service
Connect you with peers and supportersProfile and match choices, availability, messaging routingProviding the Service
Process subscriptions and products we sellAccount, commerceContract and transaction
Deliver a gift membershipSender account, recipient email, redemption recordTransaction; unused invitation data deleted after 12 months
Operate AI featuresAI input and output, provider metadata, context you selectedYour request; separate sensitive-data consent where required
Moderate and protect membersReports, accessible or reported content, account and device, safety and legal recordsSecurity, rule enforcement, legal obligation
Essential operational metricsFeature counts and reliability measures without health content or free textOperating and securing the Service
Optional product analyticsScreen, journey, and error events under a separate revocable tokenSeparate opt-in
Optional recovery researchOnly the data listed in Section 13, under an independent tokenSeparate opt-in and research consent
Optional AI/ML trainingOnly the categories you check in Section 14Separate opt-in
Comply with lawRelevant recordsLegal obligation; establishing or defending claims

We will not use consumer health data for a materially different purpose without the notice and consent the law requires.

7. How we separate your data

We deliberately keep four layers apart so that a single system does not hold both your identity and your health detail:

  1. Account identity. Contact and account data in an isolated store of personal information.
  2. Service activity. Your activity in the Service stored under an opaque, salted account token. Nickelsense can re-link service activity to your account through the account-to-token derivation. That link is restricted to the application and to authorized engineering staff under logged access controls, so this layer is pseudonymous, not anonymous.
  3. Optional analytics. Analytics events under a separate, random, revocable ai_token.
  4. Optional research. Research contributions under an independently generated ai_research_token that is not derived from your account.

The analytics token map and the research token map are separate from each other and from the account store. Participating in either program is optional and does not change feature access.

Layers 1 and 2 are not anonymous, and we do not describe them that way. Staff access to each layer is role-separated and logged, as described in Sections 18 and 19.

8. Mobile app and device permissions

The App requests device permissions just in time, when a feature needs them, and explains why at the moment of the prompt. You can change or revoke any permission in your device settings at any time; the only consequence is that the feature requiring it stops working.

PermissionWhy the App asksWhat leaves your device
NotificationsDeliver messages, reminders, meeting alertsPush token and notification payload. We keep sensitive detail out of lock-screen text
Contacts matchingHelp you find people you already know who opted inOnly SHA-256 hashes generated on your device. We do not upload your address book, names, or numbers
MicrophoneVoice input and live audio sessionsAudio stream while a session or recording you started is active
Camera and photo libraryProfile image, uploads, video sessionsOnly the media you select or capture
LocationFind meetings near you (mobile App only, and only if you turn location on)Your device location while location is on and you use the meeting finder; on the web, location is not collected from your device. We do not use geofences around health-care facilities
Health app integrationNot integratedNothing. The App does not read from or write to Apple Health or Google Health Connect

App-store platforms also receive their own data when you download, update, or purchase in the App. Apple and Google act as independent parties for those activities under their own policies. Our app-store privacy labels (Apple App Store privacy label, Google Play Data safety section) must match this policy — we maintain them together.

Optional analytics, optional research, and optional AI training each have separate in-app choices and are never bundled into a device permission prompt or into your acceptance of the Terms.


Part III — Tracking technologies

9. Cookies, SDKs, and similar technologies

"Cookie" here includes cookies, SDKs, local storage, pixels, tags, device identifiers, embedded players, and similar technologies on both web and mobile.

Our approach. Because Parachute | Tether | Tandem handles recovery and mental-health information, we use essential technologies to authenticate you, secure the Service, remember your privacy choices, and deliver features you request. We use optional first-party analytics only after you opt in. We do not permit advertising pixels, cross-context behavioral advertising, data-broker enrichment, or session replay on sensitive surfaces.

Technology / providerTypeDataPurposeDurationYour choice
Session cookie / secure sign-in tokenFirst-party essentialRandom session tokenSign-in and security14 daysRequired
Privacy-choice recordFirst-party essentialConsent version and preferencesRemember your choices12 monthsRequired
Rate-limit and CSRF tokensFirst-party essentialRandom token, IP security signalPrevent abuseUp to 24 hoursRequired
PostHog product analytics (self-hosted by Nickelsense)OptionalScreen and event names, coarse device, random analytics tokenProduct improvement12 monthsOpt-in
Sentry error and crash reportingThird-partyError type, app and device, redacted stack and logsReliability90 daysEssential: needed to detect and fix crashes and security errors; text, URLs, and identifiers are redacted before sending
LiveKit (voice and video)FunctionalMedia stream, IP, device and quality metadataThe live call you startSession / the call; connection logs up to 30 daysYou start the call
Embedded media players (for example, video or podcast hosts)FunctionalIP, device, content IDPlay media you requestProvider's policyPrior notice and consent

Your choices. Use Settings → Privacy → Cookies and tracking (or the cookie banner on the website) to allow or reject: essential (always active), functional media and live features, product analytics, and — through its own separate notice, never bundled here — AI improvement. Rejecting optional technologies does not block core features. We honor legally required browser and device preference signals, including the Global Privacy Control (GPC) signal.

10. Sensitive surfaces where trackers are prohibited

The following surfaces must never load an advertising tracker or session-replay tool: signup, intake, recovery or mental-health profile, check-ins, sobriety date, search, Hubb and meeting and provider pages when authenticated, support requests, AI chat, direct messages, journal, groups, live sessions, crisis resources, billing, and privacy requests.

Diagnostic tools operating on these surfaces must redact, before transmission, all text fields, URLs and query strings, health attributes, contact data, message bodies, screenshots, and stable account identifiers.

11. Recording, session replay, and video

Session replay. We do not use session replay unless we first identify the specific feature, obtain prior all-party consent, apply a redaction scheme, and publish the purpose, provider, and retention in this section. We do not currently use session replay anywhere in the Service. Any consent must be obtained before recording starts; consent cannot operate retroactively.

Live meetings. We do not record a live voice or video meeting without a clear in-session indicator and each participant's legally sufficient prior consent. Recording is turned off by default. A host may turn recording on for a session only if every participant sees a clear notice before recording starts and gives any prior consent the law requires. Recordings may be analyzed by automated tools, including AI, to detect keywords for safety and aggregate research, without your name, account ID, or other account identity attached to that analysis. Recordings are deleted after 30 days unless preserved for a safety report or legal hold.

Video privacy. We do not send a member's identity or a persistent account or device identifier together with video or audio titles to a third party unless it is necessary to play content you requested and supported by a stand-alone consent where the Video Privacy Protection Act applies. We audit embedded players before each release.


Part IV — Optional programs, each separately consented

Three programs are optional. Each has its own consent, its own withdrawal path, and its own data boundary. None of them is required for any feature, and declining any of them does not reduce your access or change your price.

12. Optional product analytics

With your separate permission, we collect events such as screen opened, feature used, response time, failure, and coarse journey completion, recorded under a random, revocable analytics token.

Product analytics excludes: post, message, or journal text; health answers and check-in content; search terms; exact location; advertising identifiers; and direct account or contact identifiers.

Turning analytics off stops future optional events and severs (deletes) the token map. Essential aggregate counts necessary to operate and secure the Service continue, and they contain only the feature or event name, count, success or error status, app version, platform, and date — with no account token, health content, or free text.

13. Optional recovery research

Research participation requires a separate affirmative opt-in and is governed by the Research Consent at research-consent.html. Declining has no effect on the Service.

What research includes:

What research never includes: your name, email, phone, exact address or city, exact dates, direct messages, journals, safety reports, moderation records, or the retained text of your posts.

Small-group thresholds. No statistic is produced from fewer than 10 people. Nothing is shared outside Nickelsense below 30 distinct people. A vocabulary term is retained only after at least 30 distinct people have used it.

Language pipeline. For opted-in, eligible post text only, the research pipeline converts text into numerical features and then discards the pipeline's working textual copy. The Service still stores your original post so it can be displayed — that is Service storage, not research storage. The pipeline does not retain a source sentence, fragment, surrounding context, or any mapping from a vocabulary term back to a person. Direct messages and journals are never analyzed for research.

Withdrawal: sever, not delete. When you withdraw, we destroy the link between your account and your research token. Rows you already contributed remain, because after the token map is destroyed neither we nor you can identify which rows were yours. New contributions stop immediately. If any remaining data is reasonably linkable to you by another method, it must be treated as personal data and this paragraph must be revised.

14. Optional AI/ML model training

This program materially expands what we may do with your information. It is entirely optional, presented separately, and never bundled with the Terms, analytics, research, marketing, or ordinary AI-feature use.

The distinction that matters. Operating an AI feature to answer your current request is one thing. Using your information to train or fine-tune a reusable model is a different thing. We will not use identifiable or pseudonymous consumer health data, private messages, journals, voice recordings, or AI conversations to train or fine-tune a reusable model unless you separately opt in.

What we use without a separate opt-in. We continuously use aggregate engagement statistics — for example, how often features are used and which kinds of content and actions members engage with — to operate the Service and to improve and train our systems, including our AI models. These statistics contain no name, contact information, or account identifier, no text you write, and no health or recovery answers, and they are analyzed only in aggregate. Anything beyond that requires the opt-in below.

14.1 The choice you are offered

"Help improve Nickelsense AI?" If you choose Yes, Nickelsense may use only the categories you check below to train, fine-tune, evaluate, and improve Nickelsense's AI models (models we host ourselves and models we fine-tune through our AI providers) for the purposes listed in Section 14.2. Choosing No does not reduce your access to core features.

Categories are individually selectable and start unchecked:

Never eligible, regardless of consent: direct messages, journals, crisis and safety reports, moderation reports, credential documents, payment data, precise location, contact lists or hashes, voiceprints or raw voice, and information about another person.

14.2 Model, purpose, and recipients

Model owner: Nickelsense Inc.
Model name and version: Nickelsense AI models (the model version in use is shown in the App when you opt in)
Purpose: Improve recovery-resource recommendations, detect unsafe AI output, and improve the tone and helpfulness of AI peer-support responses
Who can use the trained model: Nickelsense brands (Parachute, Tether, Tandem) and white-label installations operated by Nickelsense
Commercialization: Not sold or licensed separately; made available only as part of the Service, including white-label installations

We and our processors may use selected data only to prepare a controlled training corpus, train or fine-tune, evaluate safety, quality, and bias, and audit the named model for the named purpose. A materially different model, recipient, or purpose requires a new choice.

If you opt in, you grant Nickelsense a nonexclusive, worldwide, royalty-free license to use the selected content for the stated training purpose during the consent period. It does not transfer ownership and does not authorize advertising, sale of your source content, identification of you, or unrelated model training.

14.3 What we do before training

  1. Confirm you are 18 or older and record your consent version and provenance.
  2. Remove direct identifiers and unnecessary metadata.
  3. Exclude named third parties and high-risk content.
  4. Generalize or suppress dates, location, rare attributes, and small groups.
  5. Keep the corpus key separated from account systems.
  6. Prohibit re-identification and provider secondary use by contract.
  7. Test for memorization, extraction, membership inference, and disparate performance.
  8. Apply the HIPAA de-identification standards (Safe Harbor or Expert Determination) as an engineering benchmark.

Deidentified does not mean risk-free. Rare attribute combinations and model memorization can create residual risk, and HIPAA methods are a benchmark rather than proof of compliance with every state law. We will not call data anonymous merely because direct identifiers were removed.

14.4 Processors and training restrictions

Each AI provider we use for training (Anthropic, OpenAI, Google, or xAI, as applicable) processes only the deidentified training examples you selected in the United States for the duration of the training job, and no longer than our contract allows. Our required default position is that the provider may not use your data to train its own or other customers' models, for advertising, sale, profiling, or re-identification, and must delete source data at the end of the contract.

14.5 Retention and withdrawal

Source examples stay linked to your consent record for 24 months or until you withdraw, whichever comes first so we can honor a withdrawal, then are deleted. Training datasets and checkpoints are retained for 24 months. Model versions are retained for as long as the model version is in use, plus 12 months for security and audit purposes.

Withdraw at Settings → Privacy → AI training. Withdrawal:

An honest limit: a model that has already been trained may not permit us to isolate one person's influence. We will not promise individual "model deletion" unless it is technically supported. We will tell you what remediation we completed and identify any lawful exception we relied on.

14.6 Consent mechanics

These boxes are unchecked by default:

Buttons: "Allow selected AI training uses" / "No thanks." We log the notice version, selected categories, model and purpose, providers, timestamp, locale, and any withdrawal and remediation.

15. How AI features process your information

When you choose an AI feature, we send your prompt, the context you selected, any voice input, and technical metadata to one of the AI providers we contract with (currently Anthropic, OpenAI, Google, or xAI) or to an AI model that Nickelsense hosts itself. The provider returns output and processes the data under our contract solely for generating the response you requested and for safety and abuse monitoring.

Do not enter another person's sensitive information without authority to do so. AI is not medical care and is not emergency response.


Part V — Disclosure, retention, and safety

16. When we disclose information

We disclose information only as described here.

RecipientWhat they receive and why
Hosting: U.S.-based cloud hosting and infrastructure providers (United States); Cloudflare (content delivery and file storage); Backblaze (encrypted backups)All Service data, encrypted where described in Section 19; infrastructure and storage
Email: SendGrid (Twilio Inc.)Email address, message metadata; transactional email
Push: OneSignal, Apple Push Notification service, and Google Firebase Cloud MessagingPush token and notification payload; sensitive detail kept out of lock-screen text
SMS: TwilioPhone number and message content; only if you enable SMS
Voice and video: LiveKitMedia stream and connection metadata for a session you join
AI: Anthropic, OpenAI, Google, and xAI (as configured for each feature)The prompt and context you selected, and the output
Payments: StripePurchase and account metadata; payment processing
Error monitoring: SentryError type, app and device details, and redacted logs; reliability and security
App billing: Apple or Google (only if in-app purchases are offered)Subscription, app, account, and device identifiers
Sponsored-install administratorAccount and membership status, seat or sponsorship usage, and aggregate engagement reports for that installation, to administer the sponsorship — not your private messages, journals, or check-in answers
Other members and the publicThe content and profile fields you chose to share with that audience
Research partnersOnly aggregate, deidentified summary statistics meeting the 30-person external threshold, sold or licensed under contracts that prohibit re-identification, and only from members who opted in to research
Sponsors and advertisersNothing about you. Sponsors receive only aggregate placement counts, such as impressions and clicks
Professional advisers and insurersThe minimum necessary for legal, audit, security, or claims purposes
Authorities and safety recipientsWhere required by law, or reasonably necessary under the approved serious-harm protocol in Section 18
A successor in a transactionSubject to notice, purpose limits, and any consumer-health-data consent or authorization requirement

We do not sell personal information or consumer health data, and we do not share it for targeted or cross-context behavioral advertising. What we do sell, and to whom. Only if you opt in to recovery research (Section 13, in Settings), we may sell or license aggregate, deidentified summary statistics — never records about an individual — to researchers, health-care providers, and organizations working to improve long-term mental health and recovery. Each statistic reflects at least 30 different members and contains no name, contact information, account identifier, or text anyone wrote. We do not consider these summaries personal information or consumer health data, because they cannot reasonably be linked to you. We never sell or give any data to advertisers.

Sponsors and advertising. At launch, sponsor placements in the Service are untargeted: every member who views that part of the Service can see the same placement. In the future we may offer targeted sponsor placements. If we do, we will run every placement ourselves, a placement will never be shown to an audience smaller than 500 members, and we will never give a sponsor or advertiser your personal information, health information, or account identifiers. Any use of your information to target a placement will require your express consent in Settings. Sponsors receive only aggregate counts, such as impressions and clicks. Promotional emails or texts about a partner are sent by us, only to members who opted in to marketing; we do not give your email address or phone number to a partner.

17. Retention and deletion

CategoryHow long we keep it
Open account and contentWhile your account is active, then deleted as described in the rows below after you delete your account
Deleted-account grace period30 days, cancellable by you
Personal information after the grace periodDeleted from active systems within 30 days
Your contentDeleted; copies other members received follow their own copy; messages and content you already delivered to other members may remain visible to them, shown without your profile details
Commerce and tax records5 years, then deleted or deidentified
Safety and moderation records3 years; longer for severe or repeated abuse, or under legal hold
Credential documents3 years after the application decision or the credential's expiration, whichever is later
Support tickets2 years
AI input and output90 days
Security and access logs90 days
BackupsAge out within 30 days; isolated from ordinary use
Analytics and research token mapsUntil you withdraw or delete your account, then severed
Validated anonymous research rowsRetained indefinitely after validated anonymization
Unredeemed gift recipient email12 months

Deletion may be delayed for security, fraud prevention, a legal obligation, a litigation hold, or another statutory exception. Where law requires, we will identify the specific exception in our response to you.

18. Safety and legal disclosures

The Service is not an emergency service. See Section 6 of the Terms.

The self-assessment safety flag displays crisis resources and asks you to act on them. It does not alert staff, your contacts, or any authority. We keep a record that the resources were displayed.

Staff access. Authorized staff may review public content, content submitted for prepublication review, and content reported to us under the moderation process described in Section 13 of the Terms. Access is role-separated and logged. We do not continuously monitor direct messages, journals, support requests, AI conversations, or check-in answers.

Serious and imminent threats. If information actually available to authorized staff indicates a serious and imminent threat to life or safety, we may disclose the minimum necessary information where law permits or requires, under our internal safety protocol.

Legal requests. We respond to a subpoena, warrant, court order, or other lawful request after review, disclosing only what is required. Where law permits, we notify the affected member.

19. Security

We use administrative, technical, and physical safeguards designed for the sensitivity of this data, including encryption at rest for journal entries, recovery-profile fields, check-in card answers, research answers, and private messages, TLS encryption in transit, opaque salted account tokens in application data, role-separated administrative access, server-side enforcement of your privacy choices, session controls, access logging, vendor security review, and documented incident response.

Private messages are encrypted at rest. Private messages are not end-to-end encrypted: our servers can decrypt them to deliver them to the recipient, and authorized staff access a message only when it is reported to us or when required for safety or legal reasons.

No system is perfectly secure. Use a strong, unique password, enable two-factor authentication where offered, and tell us at security@nickelsense.com if you suspect a problem.

20. Breach notification

We maintain a process to assess incidents under state breach-notification laws, the FTC Health Breach Notification Rule, HIPAA and 42 C.F.R. Part 2 where applicable, and our contracts.

The Health Breach Notification Rule can treat an unauthorized disclosure — not only a malicious intrusion — as a breach. We will notify affected people, regulators, and others as and when required, and we will describe what happened, what data was involved, and what we are doing about it.


Part VI — Your rights

21. Consumer health data notice

This section is provided for laws including the Washington My Health My Data Act and Nevada SB 370.

We obtain separate consent before collecting or sharing consumer health data where required, and a separate signed authorization before any sale. We do not use geofences around health-care facilities to identify, track, or collect consumer health data.

On a valid request, we delete covered consumer health data from active systems and instruct our processors, affiliates, and other recipients to delete it — subject to the legal exceptions and backup timelines in Section 17.

22. Your rights and how to exercise them

Depending on where you live and which law applies, you may have the right to:

How to submit a request: Settings → Privacy in the App, Settings → Privacy on the website, or privacy@nickelsense.com. We verify requests proportionately to their sensitivity using your signed-in account, or — for email requests — a verification code sent to the email address or phone number on the account, respond within the applicable statutory period, and explain your appeal rights if we decline. An authorized agent must provide written, signed permission from you, and we may ask you to confirm your identity directly with us. We honor the Global Privacy Control (GPC) signal for legally required opt-outs.

No penalty for declining. We will not charge you more or reduce your access because you declined optional analytics, research, or AI training, or because you exercised a right — except where law expressly permits a proportionate difference directly related to the value of the data and we give you the required notice.

23. Children

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has an account, contact privacy@nickelsense.com. We will investigate, restrict access, and delete information as required. If you indicate during signup that you are under 18, we stop the signup and do not keep the information you entered.

24. International use

The Service is intended for use in the United States only. Our systems and providers process data in the United States. Please do not use the Service from another country unless we have published a country-specific supplement that permits it. If we later permit international use, we will implement the transfer safeguards required by applicable law (such as Standard Contractual Clauses) and a local supplement and publish Annex B.

25. Changes to this policy

We will post changes with a new effective date and version number, and give advance in-app and email notice of material changes. Before a new or materially different consumer-health-data purpose, research use, disclosure, or AI-training use, we will obtain fresh consent where required — we will not quietly widen an existing policy to cover a new use. Archived versions are available at archive.html.

26. Contact and complaints

Nickelsense Privacy Team
Nickelsense Inc.
Louisville, Kentucky
privacy@nickelsense.com · Settings → Privacy (in the App or on the web)
Appeals: appeals@nickelsense.com

You may also complain to the regulator or Attorney General with jurisdiction over you.


Annex A — California notice at collection

In the preceding 12 months, we collected the categories of personal information listed in Section 4, for the purposes listed in Section 6, and disclosed them to the categories of recipients listed in Section 16.

Nickelsense may not currently meet the thresholds to be a "business" under the California Consumer Privacy Act. We nonetheless provide the notice and rights in this Annex to California residents. We do not sell or share personal information as those terms are defined in the CCPA. We retain each category as described in Section 17. Sensitive personal information is used only for providing the Service you request, security and integrity, and other purposes permitted under Cal. Code Regs. tit. 11, § 7027(m).

California residents may exercise the rights in Section 22 at Settings → Privacy or privacy@nickelsense.com (because the Service is offered only online and we have a direct relationship with you, we accept requests by email instead of a toll-free number).


Annex C — Consent inventory: which choice controls what

ChoiceWhat it permitsWhere you make or change itEffect of declining
Terms acceptanceThe contract; core Service processingSignup checkboxCannot use the Service
Consumer health data collection consentCollecting recovery and mental-health fields where a state law requires separate consentIntake, just in timeThat optional field or feature is unavailable
Consumer health data sharing consentSharing with a named recipient categoryPrivacy centerNo sharing
Signed authorization for saleAny statutory "sale"Separate signed formNone occurs
Cookie and tracking preferencesFunctional media, optional analytics technologiesSettings → Privacy → Cookies and trackingEssential only; all core features work
Product analytics opt-inSection 12 events under a revocable tokenPrivacy centerNo effect on features or price
Research consentSection 13 data under an independent tokenresearch-consent.htmlNo effect on features or price
AI/ML training opt-inOnly the categories checked in Section 14ai-training.htmlAI features still work normally
Device permissionsThe specific device capabilityDevice settingsOnly that feature stops
Marketing communicationsPromotional email or pushNotification settingsService notices still sent
Recording consentA specific recording, before it startsIn-session promptNo recording

Rule: no item in this table may be bundled with, or made a condition of, any other item.


Other legal documents

Nickelsense Inc. · Louisville, Kentucky · legal@nickelsense.com · (502) 354-8105