Consumer Health Data Policy

Effective date: August 13, 2026 · Applies to: Auditend, Inc. · Contact: support@auditend.com

This is a standalone policy, separate from our general Privacy Policy.

Auditend creates verifiable records that you attended recovery or support meetings (AA, NA, CA, MA, SMART Recovery, Recovery Dharma). Information that reveals your participation in recovery — your attendance, your location at check-in, and your check-in selfie video — is consumer health data. This policy explains what we collect, why, who can see it, how long we keep it, and the rights you have.

Auditend is for adults 18 or older. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.

What we collect and why

DataWhat it isWhy we collect it
Account & identityName, email, authenticated user IDOperate your account; your name appears on reports you generate
Meeting attendanceMeeting selected, recovery fellowship (if applicable), scheduled meeting information, and date and time of check-inBuild your attendance record and reports you request
Location at check-inRetained as a general area (~city block) with a GPS accuracy value. The precise coordinate is discarded once the general area is derived — it is not retained.Your attendance record and the coarse-area map shown on your reports
Selfie video at check-inA short selfie video used to verify your identity and help protect the integrity of your attendance record (see Biometric section)Ties the record to you; protects your record against fraud
Device-integrity signalsMock-location flag, device model/OS, app versionFraud protection for your record
Consent & authorization recordsYour consent version/timestamp; each sharing authorizationLegal proof of your permissions
Saved report-recipient contextIf you choose to save a recurring recipient: name, work email, role, and optional agency. A role or agency associated with your account may reveal health-related or supervision context.Let you reuse a recipient you selected. Saving does not contact the recipient, share a report, or grant access.
Access logsWho viewed your shared reports and whenSo we can show you, on request, who accessed your records

Source: account and consent information comes from you; saved recipient details come from information you choose to enter; capture information comes from you and your device; meeting reference details come from public meeting directories; and report-access logs come from recipients you authorize. We do not buy health data about you or infer diagnoses from your records.

What we never do

We never sell your data. We never use it for advertising or share it with advertisers. We do not use tracking pixels or advertising SDKs. We do not create faceprints or perform face recognition. We do not use automated location boundaries ("geofences") around meetings or judge your distance from a venue. We do not train AI models on your identifiable records.

Who can see your data

  • Recipients you choose. Reports are shared only at your direction. Each disclosure requires your separate, specific, revocable authorization identifying the recipient, report scope, and access period. You may add a reason, but a written reason is not required to authorize sharing. Each authorization applies only to that individual disclosure and does not authorize future disclosures. Every view of a shared report is logged and time-limited. Saving a recipient for reuse does not contact that person or authorize any disclosure.
  • Only your general area (approximately a city block) is ever stored or shown. We do not retain your exact location, so there is no precise coordinate to display; reports show a coarse-area map, never an exact pin or address.
  • Service providers under contract, only to operate the service and restricted to their contracted services: Supabase (hosting, database, authentication, file storage), Sentry (crash/performance diagnostics, scrubbed of personal and health data), Postmark (transactional email — sign-in codes and report delivery), Geoapify (coarse-area map images shown on reports), and Google Places (meeting-address lookup). Report PDFs/images are rendered by Gotenberg on Auditend-controlled infrastructure hosted by Fly.io. When a user purchases a subscription, Apple and RevenueCat process in-app purchase and subscription information; Stripe processes web subscription purchases. Auditend receives subscription status and transaction identifiers but does not receive or store full payment-card numbers. We have no affiliates.
  • Legal process. If we are compelled by a valid court order or subpoena, we disclose only what the order requires, and where lawful we will notify you.

Your selfie video is treated as biometric information

We do not create, store, or transmit a faceprint, biometric template, facial embedding, or face-recognition identifier, and we never perform face recognition or matching. During capture, on-device software (Google ML Kit) transiently checks that a face is present and centered in the frame; that framing check is not retained and does not build a face template. We treat the selfie video as biometric information anyway and apply the strictest standard: collected only with your written consent (the consent screen); never sold, never used for advertising, and never a source of profit. It becomes eligible for destruction under the schedule below; an active legal or record-preservation obligation may delay destruction, and a non-reversible integrity hash may remain after the video is removed.

How long we keep things (retention schedule)

DataKeptThen
Selfie videosEligible 30 days after authenticated report delivery, or 3 years after capture if no earlier delivery-based date; an active legal or record-preservation obligation may delay deletionStorage object and mutable pointer destroyed; non-reversible integrity hash may remain
Precise (exact) coordinatesNot retainedDiscarded during check-in once the approximate area is derived. Limited legacy records that had sealed an exact coordinate are being deleted.
General-area location payloadSame eligibility rule as selfie videos; an active legal or record-preservation obligation may delay deletionGeneral-area payload removed; non-reversible integrity commitment may remain
Attendance records and generated reportsWhile needed to provide the service and support reports you requestDeleted or de-linked on an eligible deletion request, except for the minimum integrity record described below
Saved report recipientsUntil you remove the saved recipient or delete your accountDeleted from the address book; not retained as part of the signed report-integrity record. A separately authorized access grant remains subject to its own expiry or revocation.
Signed integrity recordsRetained when needed to preserve an already-issued report or satisfy a documented legal or record-preservation obligationAfter evidence shredding, the retained integrity skeleton contains hashes and signatures rather than removed media or readable location payload
Consent & authorization recordsRetained as permission and audit records while needed for legal and security purposesRemoved when the applicable retention requirement expires; no automated six-year purge is represented as live until implemented
Access logsRetained for access security, audit, and rights-response purposesRemoved when the applicable retention requirement expires; no automated six-year purge is represented as live until implemented

Deletion currently reaches Auditend's operational database and private file storage. We notify processors and other recipients of deletion requests when applicable law requires it and track those requests through completion. Archived or backup copies age out through controlled provider lifecycles; we do not represent them as removed before that process completes. If a documented legal or record-preservation obligation requires a minimum integrity record, we explain what is retained and why.

Your rights

You may at any time access the data we hold about you; delete eligible data; withdraw consent to future core attendance-evidence collection in Settings; and separately revoke active report-sharing access. You may also add, update, or remove saved report recipients, and those profiles are included in your data export. Withdrawing collection consent does not itself delete information already collected or revoke a report-access grant. After withdrawal, Auditend blocks new check-ins unless you affirmatively consent again.

Exercise rights in Settings, or email support@auditend.com with "Privacy Request" in the subject line. We verify in-app requests using your authenticated account and may request only information reasonably necessary to authenticate an emailed request. We respond without undue delay and within 45 days. When reasonably necessary, we may extend once for up to 45 additional days; we notify you during the initial period and explain why. We never discriminate against you for exercising a right.

If we refuse to act, we provide our reasons and explain how to appeal. Submit an appeal to support@auditend.com with "Privacy Appeal" in the subject line. We decide an appeal within 45 days and, if it is denied, provide the applicable Attorney General complaint method.

A note on court obligations: if your records are subject to an active court or program obligation, we preserve the minimum required through that obligation, then complete your deletion. We document the legal basis and timing and tell you when deletion completes.

Security

Health data is protected with row-level access controls, private storage with short-lived signed URLs, restricted storage for legacy exact-coordinate records (where applicable), cryptographic signing of records at capture, scrubbed logging and crash reporting, and least-privilege access. Public report verification exposes authenticity only — never your health data.

Changes and contact

Material changes to this policy require your renewed consent before they apply to you. Questions or rights requests: support@auditend.com · Auditend, Inc., 131 Continental Drive, Suite 305, Newark, DE 19713.