Consumer Health Data Policy
Effective date: at app release · Applies to: Auditend, Inc. · Contact: privacy@auditend.com
This is a standalone policy, separate from our general Privacy Policy.
Auditend creates verifiable records that you attended recovery or support meetings (AA, NA, CA, MA, SMART Recovery, Recovery Dharma). Information that reveals your participation in recovery — your attendance, your location at check-in, and your check-in selfie video — is consumer health data. This policy explains what we collect, why, who can see it, how long we keep it, and the rights you have. We follow the strictest applicable state standard for everyone, regardless of where you live.
Auditend is for adults 18 or older. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
What we collect and why
| Data | What it is | Why we collect it |
|---|---|---|
| Account & identity | Name, email, authenticated user ID | Operate your account; your name appears on reports you generate |
| Meeting attendance | Meeting selected, fellowship, date/time of check-in | Build your attendance record and reports you request |
| Location at check-in | Retained as a general area (~city block) with a GPS accuracy value; exact coordinates kept in restricted, sealed storage | Part of the sealed evidence record you may choose to show a reviewer |
| Selfie video at check-in | A short video used as an identity anchor (see Biometric section) | Ties the record to you; protects your record against fraud |
| Device-integrity signals | Mock-location flag, device model/OS, app version | Fraud protection for your record |
| Consent & authorization records | Your consent version/timestamp; each sharing authorization | Legal proof of your permissions |
| Access logs | Who viewed your shared reports and when | So we can show you, on request, who accessed your records |
Source: everything above comes from you and your device. We do not buy, collect, or infer health data about you from anyone else.
What we never do
We never sell your data. We never use it for advertising or share it with advertisers. We do not use tracking pixels or advertising SDKs. We do not create faceprints or perform face recognition. We do not use automated location boundaries ("geofences") around meetings or judge your distance from a venue. We do not train AI models on your identifiable records.
Who can see your data
- Recipients you choose. Reports are shared only at your direction (e.g., a court, probation officer, or attorney), and each share requires your separate, specific, revocable authorization naming the recipient. Every view of a shared report is logged and time-limited.
- Your exact location is shown to no one by default. A reviewer sees it only if you authorize that specific request, or if a court compels it through legal process. Each disclosure is individually logged.
- Service providers under contract, only to operate the service, barred from any other use: Supabase (hosting/database), Sentry (crash reporting, scrubbed of health data), PostHog (analytics, configured to receive no personal or health data), RevenueCat and Stripe (subscriptions/payments — pseudonymous identifiers, no health data), Postmark (transactional email). Report PDFs are rendered on our own infrastructure; no outside service receives report contents. We have no affiliates.
- Legal process. If we are compelled by a valid court order or subpoena, we disclose only what the order requires, and where lawful we will notify you.
Your selfie video is treated as biometric information
We do not derive a faceprint, template, or any measurement of face geometry, and we never perform face recognition or matching. We treat the selfie video as biometric information anyway and apply the strictest standard: collected only with your written consent (the consent screen); never sold, never used for advertising, never a source of profit; destroyed when its purpose is satisfied or within 3 years of your last interaction with Auditend, whichever comes first.
How long we keep things (retention schedule)
| Data | Kept | Then |
|---|---|---|
| Selfie videos | Purpose satisfied or ≤3 years, whichever first | Destroyed |
| Exact (sealed) coordinates | Through your active court/program obligation + 90 days | Cryptographically shredded (unrecoverable) |
| General-area location & attendance records | While your account is active | Deleted/anonymized on deletion request |
| Generated reports | 1 year after creation | Deleted |
| Signed integrity records | Retained | Contain no readable health data after shredding; keep your past reports verifiable |
| Consent & authorization records | 6 years | Deleted |
| Access logs | 6 years | Deleted |
Deletion reaches our database, file storage, and service providers.
Your rights
You may at any time: access the data we hold about you (for your safety, an access response describes but does not transmit your biometric data or exact coordinates — we tell you we hold them rather than sending them); delete your data; withdraw consent (we stop collecting; withdrawal is as easy as giving consent); revoke any sharing authorization; and appeal any decision we make on a request.
Exercise rights in Settings, or email privacy@auditend.com. We verify requests using your authenticated account. We respond within 45 days (one 45-day extension for complex requests, with notice). If we deny a request, we explain why and you may appeal; appeal decisions within 45 days, with instructions for contacting your state Attorney General if you disagree. We never discriminate against you for exercising any right.
A note on court obligations: if your records are subject to an active court or program obligation, we preserve the minimum required through that obligation, then complete your deletion. We document the legal basis and timing and tell you when deletion completes.
Security
Health data is protected with row-level access controls, private storage with short-lived signed URLs, restricted sealed storage for exact coordinates, cryptographic signing of records at capture, scrubbed logging and crash reporting, and least-privilege access. Public report verification exposes authenticity only — never your health data.
Changes and contact
Material changes to this policy require your renewed consent before they apply to you. Questions or rights requests: privacy@auditend.com · Auditend, Inc., 131 Continental Drive, Newark, DE 19713.