Operator: Nickelsense Inc.
Applies to: Parachute, Tether, and Tandem websites at https://myparachute.live, https://mytether.live, and https://mytandem.live, Parachute, Tether, and Tandem for iOS, Parachute, Tether, and Tandem for Android, and related services
Effective: October 2, 2026
Last updated: October 2, 2026
Version: 1.0
This policy is a notice. It is not a substitute for a separate consent, authorization, cookie choice, research consent, or AI-training consent where the law requires one. Each of those choices is presented to you separately.
Part I — The short version
Part II — What we collect and why
Part III — Tracking technologies
Part IV — Optional programs, each separately consented
Part V — Disclosure, retention, and safety
Part VI — Your rights
Annexes
A. California notice at collection
C. Consent inventory (which choice controls what)
Parachute | Tether | Tandem is a peer-support and information service operated by Nickelsense Inc.. It is not medical care and it is not an emergency service.
Recovery status, substance-use focus, mental-health focus, meeting attendance, check-in scores, and even the fact that you use this app are highly sensitive. We treat them as consumer health data whether or not a specific law requires it.
In plain terms:
This policy applies to https://myparachute.live, https://mytether.live, and https://mytandem.live, the Parachute, Tether, and Tandem iOS app, the Parachute, Tether, and Tandem Android app, and the related consumer Service operated by:
Nickelsense Inc.
Louisville, Kentucky
privacy@nickelsense.com
Settings → Privacy (in the App or on the web)
Sponsored or white-label installations. If you use a separately branded installation sponsored by an employer, provider, treatment center, or other organization, review that deployment's specific notice. Nickelsense and the sponsoring organization may hold different controller, business, or processor roles depending on who determines each purpose and means of processing. For the Parachute, Tether, and Tandem services described in this policy, Nickelsense Inc. decides how and why your information is processed. For a sponsored or white-label installation, the roles of Nickelsense and the sponsoring organization are stated in that installation's own notice and in our contract with the sponsor.
What this policy does not cover. It does not cover an external provider, meeting, fellowship, facility, employer, payment app, app store, AI provider's own consumer services, or any site you reach through a link. Those parties have their own policies.
HIPAA. The direct-to-consumer Service generally is not offered by a HIPAA covered entity, and Nickelsense generally is not acting as a HIPAA business associate for information you enter directly into the consumer Service. That means information you enter here may not receive HIPAA protection. A particular sponsored installation or health-system integration may be different and will provide additional notice.
42 C.F.R. Part 2. Nickelsense is not a "part 2 program" merely because members discuss substance-use recovery. Information you provide directly to the consumer Service may not receive Part 2 protection. If a Part 2 program transmits records into a sponsored installation, additional restrictions and notices apply.
What does protect this data. State consumer health data laws — including the Washington My Health My Data Act and Nevada SB 370 — state comprehensive privacy laws, the FTC Act, the FTC Health Breach Notification Rule, and our own contractual and technical commitments in this policy.
| Category | Examples | Where it comes from |
|---|---|---|
| Account and contact | Email, optional phone, password hash, name or display name, city/state/ZIP, age representation | You |
| Consumer health and recovery | Recovery status and stage, primary and secondary substance focus, sobriety or recovery date (optional), mental-health focus, support-relationship type, wellbeing and check-in scores, self-assessment answers and safety flag, sponsor and recovery-plan status | You; generated from your use |
| Sensitive profile fields | Gender identity, sex at birth, race or ethnicity, religion, education, military status, profile visibility choices | You (all optional) |
| Content | Posts, comments, reactions, group material, public shares, reviews, uploads, creator materials, profile image | You |
| Private content | Direct messages, journals and notebook entries | You |
| AI data | Prompts, conversation content, voice input and output, model output, safety classification, provider and model metadata | You; AI provider |
| Support and meeting activity | Support requests, availability, connections, meeting RSVPs and attendance, live-session routing and quality metadata | You; generated |
| Commerce | Plan, purchase record, gift recipient email, transaction identifier, payment status, app-store or Stripe metadata. Not your full card number | You; payment and app-store providers |
| Specialist and creator | Certification documents, claimed credentials, listings, moderation and review records | You; issuing or public sources where checked |
| Device and network | IP address, device, app, and browser type, operating system, language, access time, push token, cookie and local-storage identifiers, crash and security logs | Your device; service providers |
| Location | City, state, ZIP, and precise or approximate device location, only if you turn on location in the mobile App to find nearby meetings | You; your device with permission |
| Contacts matching | SHA-256 hashes generated on your device from phone numbers, an opted-in member's own hash, and match results | Your device; members |
| Moderation, safety, and legal | Reports, actions taken, appeals, evidence, blocked users, legal requests, preservation records | You; other users; authorities |
| Inferences | Recovery-stage band, risk or resource-display flag, recommendations, matching and ranking signals, aggregate metrics | Generated by us |
On tokens and hashes: replacing a direct identifier with a hash or token is pseudonymization, not anonymization, for as long as a link or a reasonable method of re-identification exists. We do not describe pseudonymous data as anonymous.
Parachute may collect your addiction or recovery focus, recovery stage, an optional sobriety date, sponsor status, recovery-plan status, support requests, meeting engagement, recovery resources viewed, and — if you opt in — recovery research data.
Tether may collect the type and duration of your support relationship, supporter burnout and readiness questionnaire scores, resources you use, gifts you send, and — if you opt in — research data.
Do not enter the supported person's health or recovery information without that person's permission unless law permits it. Tether does not give you access to another person's account or records.
Tandem may collect your mental-wellness focus, wellbeing and check-in responses, support requests, community engagement, and — if you opt in — research data. Tandem does not create a clinical record.
| Purpose | Categories used | Basis or your choice |
|---|---|---|
| Create and secure your account | Account, device and security, age representation | Providing the Service you requested; security |
| Deliver the features you choose | Content, health and recovery, profile, meetings, support, location where you chose it | Providing the Service; consumer-health consent where required |
| Apply your privacy and audience choices | Identity, profile, content, connections | Providing the Service |
| Connect you with peers and supporters | Profile and match choices, availability, messaging routing | Providing the Service |
| Process subscriptions and products we sell | Account, commerce | Contract and transaction |
| Deliver a gift membership | Sender account, recipient email, redemption record | Transaction; unused invitation data deleted after 12 months |
| Operate AI features | AI input and output, provider metadata, context you selected | Your request; separate sensitive-data consent where required |
| Moderate and protect members | Reports, accessible or reported content, account and device, safety and legal records | Security, rule enforcement, legal obligation |
| Essential operational metrics | Feature counts and reliability measures without health content or free text | Operating and securing the Service |
| Optional product analytics | Screen, journey, and error events under a separate revocable token | Separate opt-in |
| Optional recovery research | Only the data listed in Section 13, under an independent token | Separate opt-in and research consent |
| Optional AI/ML training | Only the categories you check in Section 14 | Separate opt-in |
| Comply with law | Relevant records | Legal obligation; establishing or defending claims |
We will not use consumer health data for a materially different purpose without the notice and consent the law requires.
We deliberately keep four layers apart so that a single system does not hold both your identity and your health detail:
ai_token.ai_research_token that is not derived from your account.The analytics token map and the research token map are separate from each other and from the account store. Participating in either program is optional and does not change feature access.
Layers 1 and 2 are not anonymous, and we do not describe them that way. Staff access to each layer is role-separated and logged, as described in Sections 18 and 19.
The App requests device permissions just in time, when a feature needs them, and explains why at the moment of the prompt. You can change or revoke any permission in your device settings at any time; the only consequence is that the feature requiring it stops working.
| Permission | Why the App asks | What leaves your device |
|---|---|---|
| Notifications | Deliver messages, reminders, meeting alerts | Push token and notification payload. We keep sensitive detail out of lock-screen text |
| Contacts matching | Help you find people you already know who opted in | Only SHA-256 hashes generated on your device. We do not upload your address book, names, or numbers |
| Microphone | Voice input and live audio sessions | Audio stream while a session or recording you started is active |
| Camera and photo library | Profile image, uploads, video sessions | Only the media you select or capture |
| Location | Find meetings near you (mobile App only, and only if you turn location on) | Your device location while location is on and you use the meeting finder; on the web, location is not collected from your device. We do not use geofences around health-care facilities |
| Health app integration | Not integrated | Nothing. The App does not read from or write to Apple Health or Google Health Connect |
App-store platforms also receive their own data when you download, update, or purchase in the App. Apple and Google act as independent parties for those activities under their own policies. Our app-store privacy labels (Apple App Store privacy label, Google Play Data safety section) must match this policy — we maintain them together.
Optional analytics, optional research, and optional AI training each have separate in-app choices and are never bundled into a device permission prompt or into your acceptance of the Terms.
"Cookie" here includes cookies, SDKs, local storage, pixels, tags, device identifiers, embedded players, and similar technologies on both web and mobile.
Our approach. Because Parachute | Tether | Tandem handles recovery and mental-health information, we use essential technologies to authenticate you, secure the Service, remember your privacy choices, and deliver features you request. We use optional first-party analytics only after you opt in. We do not permit advertising pixels, cross-context behavioral advertising, data-broker enrichment, or session replay on sensitive surfaces.
| Technology / provider | Type | Data | Purpose | Duration | Your choice |
|---|---|---|---|---|---|
| Session cookie / secure sign-in token | First-party essential | Random session token | Sign-in and security | 14 days | Required |
| Privacy-choice record | First-party essential | Consent version and preferences | Remember your choices | 12 months | Required |
| Rate-limit and CSRF tokens | First-party essential | Random token, IP security signal | Prevent abuse | Up to 24 hours | Required |
| PostHog product analytics (self-hosted by Nickelsense) | Optional | Screen and event names, coarse device, random analytics token | Product improvement | 12 months | Opt-in |
| Sentry error and crash reporting | Third-party | Error type, app and device, redacted stack and logs | Reliability | 90 days | Essential: needed to detect and fix crashes and security errors; text, URLs, and identifiers are redacted before sending |
| LiveKit (voice and video) | Functional | Media stream, IP, device and quality metadata | The live call you start | Session / the call; connection logs up to 30 days | You start the call |
| Embedded media players (for example, video or podcast hosts) | Functional | IP, device, content ID | Play media you request | Provider's policy | Prior notice and consent |
Your choices. Use Settings → Privacy → Cookies and tracking (or the cookie banner on the website) to allow or reject: essential (always active), functional media and live features, product analytics, and — through its own separate notice, never bundled here — AI improvement. Rejecting optional technologies does not block core features. We honor legally required browser and device preference signals, including the Global Privacy Control (GPC) signal.
The following surfaces must never load an advertising tracker or session-replay tool: signup, intake, recovery or mental-health profile, check-ins, sobriety date, search, Hubb and meeting and provider pages when authenticated, support requests, AI chat, direct messages, journal, groups, live sessions, crisis resources, billing, and privacy requests.
Diagnostic tools operating on these surfaces must redact, before transmission, all text fields, URLs and query strings, health attributes, contact data, message bodies, screenshots, and stable account identifiers.
Session replay. We do not use session replay unless we first identify the specific feature, obtain prior all-party consent, apply a redaction scheme, and publish the purpose, provider, and retention in this section. We do not currently use session replay anywhere in the Service. Any consent must be obtained before recording starts; consent cannot operate retroactively.
Live meetings. We do not record a live voice or video meeting without a clear in-session indicator and each participant's legally sufficient prior consent. Recording is turned off by default. A host may turn recording on for a session only if every participant sees a clear notice before recording starts and gives any prior consent the law requires. Recordings may be analyzed by automated tools, including AI, to detect keywords for safety and aggregate research, without your name, account ID, or other account identity attached to that analysis. Recordings are deleted after 30 days unless preserved for a safety report or legal hold.
Video privacy. We do not send a member's identity or a persistent account or device identifier together with video or audio titles to a third party unless it is necessary to play content you requested and supported by a stand-alone consent where the Video Privacy Protection Act applies. We audit embedded players before each release.
Three programs are optional. Each has its own consent, its own withdrawal path, and its own data boundary. None of them is required for any feature, and declining any of them does not reduce your access or change your price.
With your separate permission, we collect events such as screen opened, feature used, response time, failure, and coarse journey completion, recorded under a random, revocable analytics token.
Product analytics excludes: post, message, or journal text; health answers and check-in content; search terms; exact location; advertising identifiers; and direct account or contact identifiers.
Turning analytics off stops future optional events and severs (deletes) the token map. Essential aggregate counts necessary to operate and secure the Service continue, and they contain only the feature or event name, count, success or error status, app version, platform, and date — with no account token, health content, or free text.
Research participation requires a separate affirmative opt-in and is governed by the Research Consent at research-consent.html. Declining has no effect on the Service.
What research includes:
What research never includes: your name, email, phone, exact address or city, exact dates, direct messages, journals, safety reports, moderation records, or the retained text of your posts.
Small-group thresholds. No statistic is produced from fewer than 10 people. Nothing is shared outside Nickelsense below 30 distinct people. A vocabulary term is retained only after at least 30 distinct people have used it.
Language pipeline. For opted-in, eligible post text only, the research pipeline converts text into numerical features and then discards the pipeline's working textual copy. The Service still stores your original post so it can be displayed — that is Service storage, not research storage. The pipeline does not retain a source sentence, fragment, surrounding context, or any mapping from a vocabulary term back to a person. Direct messages and journals are never analyzed for research.
Withdrawal: sever, not delete. When you withdraw, we destroy the link between your account and your research token. Rows you already contributed remain, because after the token map is destroyed neither we nor you can identify which rows were yours. New contributions stop immediately. If any remaining data is reasonably linkable to you by another method, it must be treated as personal data and this paragraph must be revised.
This program materially expands what we may do with your information. It is entirely optional, presented separately, and never bundled with the Terms, analytics, research, marketing, or ordinary AI-feature use.
The distinction that matters. Operating an AI feature to answer your current request is one thing. Using your information to train or fine-tune a reusable model is a different thing. We will not use identifiable or pseudonymous consumer health data, private messages, journals, voice recordings, or AI conversations to train or fine-tune a reusable model unless you separately opt in.
What we use without a separate opt-in. We continuously use aggregate engagement statistics — for example, how often features are used and which kinds of content and actions members engage with — to operate the Service and to improve and train our systems, including our AI models. These statistics contain no name, contact information, or account identifier, no text you write, and no health or recovery answers, and they are analyzed only in aggregate. Anything beyond that requires the opt-in below.
"Help improve Nickelsense AI?" If you choose Yes, Nickelsense may use only the categories you check below to train, fine-tune, evaluate, and improve Nickelsense's AI models (models we host ourselves and models we fine-tune through our AI providers) for the purposes listed in Section 14.2. Choosing No does not reduce your access to core features.
Categories are individually selectable and start unchecked:
Never eligible, regardless of consent: direct messages, journals, crisis and safety reports, moderation reports, credential documents, payment data, precise location, contact lists or hashes, voiceprints or raw voice, and information about another person.
Model owner: Nickelsense Inc.
Model name and version: Nickelsense AI models (the model version in use is shown in the App when you opt in)
Purpose: Improve recovery-resource recommendations, detect unsafe AI output, and improve the tone and helpfulness of AI peer-support responses
Who can use the trained model: Nickelsense brands (Parachute, Tether, Tandem) and white-label installations operated by Nickelsense
Commercialization: Not sold or licensed separately; made available only as part of the Service, including white-label installations
We and our processors may use selected data only to prepare a controlled training corpus, train or fine-tune, evaluate safety, quality, and bias, and audit the named model for the named purpose. A materially different model, recipient, or purpose requires a new choice.
If you opt in, you grant Nickelsense a nonexclusive, worldwide, royalty-free license to use the selected content for the stated training purpose during the consent period. It does not transfer ownership and does not authorize advertising, sale of your source content, identification of you, or unrelated model training.
Deidentified does not mean risk-free. Rare attribute combinations and model memorization can create residual risk, and HIPAA methods are a benchmark rather than proof of compliance with every state law. We will not call data anonymous merely because direct identifiers were removed.
Each AI provider we use for training (Anthropic, OpenAI, Google, or xAI, as applicable) processes only the deidentified training examples you selected in the United States for the duration of the training job, and no longer than our contract allows. Our required default position is that the provider may not use your data to train its own or other customers' models, for advertising, sale, profiling, or re-identification, and must delete source data at the end of the contract.
Source examples stay linked to your consent record for 24 months or until you withdraw, whichever comes first so we can honor a withdrawal, then are deleted. Training datasets and checkpoints are retained for 24 months. Model versions are retained for as long as the model version is in use, plus 12 months for security and audit purposes.
Withdraw at Settings → Privacy → AI training. Withdrawal:
An honest limit: a model that has already been trained may not permit us to isolate one person's influence. We will not promise individual "model deletion" unless it is technically supported. We will tell you what remediation we completed and identify any lawful exception we relied on.
These boxes are unchecked by default:
Buttons: "Allow selected AI training uses" / "No thanks." We log the notice version, selected categories, model and purpose, providers, timestamp, locale, and any withdrawal and remediation.
When you choose an AI feature, we send your prompt, the context you selected, any voice input, and technical metadata to one of the AI providers we contract with (currently Anthropic, OpenAI, Google, or xAI) or to an AI model that Nickelsense hosts itself. The provider returns output and processes the data under our contract solely for generating the response you requested and for safety and abuse monitoring.
Do not enter another person's sensitive information without authority to do so. AI is not medical care and is not emergency response.
We disclose information only as described here.
| Recipient | What they receive and why |
|---|---|
| Hosting: U.S.-based cloud hosting and infrastructure providers (United States); Cloudflare (content delivery and file storage); Backblaze (encrypted backups) | All Service data, encrypted where described in Section 19; infrastructure and storage |
| Email: SendGrid (Twilio Inc.) | Email address, message metadata; transactional email |
| Push: OneSignal, Apple Push Notification service, and Google Firebase Cloud Messaging | Push token and notification payload; sensitive detail kept out of lock-screen text |
| SMS: Twilio | Phone number and message content; only if you enable SMS |
| Voice and video: LiveKit | Media stream and connection metadata for a session you join |
| AI: Anthropic, OpenAI, Google, and xAI (as configured for each feature) | The prompt and context you selected, and the output |
| Payments: Stripe | Purchase and account metadata; payment processing |
| Error monitoring: Sentry | Error type, app and device details, and redacted logs; reliability and security |
| App billing: Apple or Google (only if in-app purchases are offered) | Subscription, app, account, and device identifiers |
| Sponsored-install administrator | Account and membership status, seat or sponsorship usage, and aggregate engagement reports for that installation, to administer the sponsorship — not your private messages, journals, or check-in answers |
| Other members and the public | The content and profile fields you chose to share with that audience |
| Research partners | Only aggregate, deidentified summary statistics meeting the 30-person external threshold, sold or licensed under contracts that prohibit re-identification, and only from members who opted in to research |
| Sponsors and advertisers | Nothing about you. Sponsors receive only aggregate placement counts, such as impressions and clicks |
| Professional advisers and insurers | The minimum necessary for legal, audit, security, or claims purposes |
| Authorities and safety recipients | Where required by law, or reasonably necessary under the approved serious-harm protocol in Section 18 |
| A successor in a transaction | Subject to notice, purpose limits, and any consumer-health-data consent or authorization requirement |
We do not sell personal information or consumer health data, and we do not share it for targeted or cross-context behavioral advertising. What we do sell, and to whom. Only if you opt in to recovery research (Section 13, in Settings), we may sell or license aggregate, deidentified summary statistics — never records about an individual — to researchers, health-care providers, and organizations working to improve long-term mental health and recovery. Each statistic reflects at least 30 different members and contains no name, contact information, account identifier, or text anyone wrote. We do not consider these summaries personal information or consumer health data, because they cannot reasonably be linked to you. We never sell or give any data to advertisers.
Sponsors and advertising. At launch, sponsor placements in the Service are untargeted: every member who views that part of the Service can see the same placement. In the future we may offer targeted sponsor placements. If we do, we will run every placement ourselves, a placement will never be shown to an audience smaller than 500 members, and we will never give a sponsor or advertiser your personal information, health information, or account identifiers. Any use of your information to target a placement will require your express consent in Settings. Sponsors receive only aggregate counts, such as impressions and clicks. Promotional emails or texts about a partner are sent by us, only to members who opted in to marketing; we do not give your email address or phone number to a partner.
| Category | How long we keep it |
|---|---|
| Open account and content | While your account is active, then deleted as described in the rows below after you delete your account |
| Deleted-account grace period | 30 days, cancellable by you |
| Personal information after the grace period | Deleted from active systems within 30 days |
| Your content | Deleted; copies other members received follow their own copy; messages and content you already delivered to other members may remain visible to them, shown without your profile details |
| Commerce and tax records | 5 years, then deleted or deidentified |
| Safety and moderation records | 3 years; longer for severe or repeated abuse, or under legal hold |
| Credential documents | 3 years after the application decision or the credential's expiration, whichever is later |
| Support tickets | 2 years |
| AI input and output | 90 days |
| Security and access logs | 90 days |
| Backups | Age out within 30 days; isolated from ordinary use |
| Analytics and research token maps | Until you withdraw or delete your account, then severed |
| Validated anonymous research rows | Retained indefinitely after validated anonymization |
| Unredeemed gift recipient email | 12 months |
Deletion may be delayed for security, fraud prevention, a legal obligation, a litigation hold, or another statutory exception. Where law requires, we will identify the specific exception in our response to you.
The Service is not an emergency service. See Section 6 of the Terms.
The self-assessment safety flag displays crisis resources and asks you to act on them. It does not alert staff, your contacts, or any authority. We keep a record that the resources were displayed.
Staff access. Authorized staff may review public content, content submitted for prepublication review, and content reported to us under the moderation process described in Section 13 of the Terms. Access is role-separated and logged. We do not continuously monitor direct messages, journals, support requests, AI conversations, or check-in answers.
Serious and imminent threats. If information actually available to authorized staff indicates a serious and imminent threat to life or safety, we may disclose the minimum necessary information where law permits or requires, under our internal safety protocol.
Legal requests. We respond to a subpoena, warrant, court order, or other lawful request after review, disclosing only what is required. Where law permits, we notify the affected member.
We use administrative, technical, and physical safeguards designed for the sensitivity of this data, including encryption at rest for journal entries, recovery-profile fields, check-in card answers, research answers, and private messages, TLS encryption in transit, opaque salted account tokens in application data, role-separated administrative access, server-side enforcement of your privacy choices, session controls, access logging, vendor security review, and documented incident response.
Private messages are encrypted at rest. Private messages are not end-to-end encrypted: our servers can decrypt them to deliver them to the recipient, and authorized staff access a message only when it is reported to us or when required for safety or legal reasons.
No system is perfectly secure. Use a strong, unique password, enable two-factor authentication where offered, and tell us at security@nickelsense.com if you suspect a problem.
We maintain a process to assess incidents under state breach-notification laws, the FTC Health Breach Notification Rule, HIPAA and 42 C.F.R. Part 2 where applicable, and our contracts.
The Health Breach Notification Rule can treat an unauthorized disclosure — not only a malicious intrusion — as a breach. We will notify affected people, regulators, and others as and when required, and we will describe what happened, what data was involved, and what we are doing about it.
This section is provided for laws including the Washington My Health My Data Act and Nevada SB 370.
We obtain separate consent before collecting or sharing consumer health data where required, and a separate signed authorization before any sale. We do not use geofences around health-care facilities to identify, track, or collect consumer health data.
On a valid request, we delete covered consumer health data from active systems and instruct our processors, affiliates, and other recipients to delete it — subject to the legal exceptions and backup timelines in Section 17.
Depending on where you live and which law applies, you may have the right to:
How to submit a request: Settings → Privacy in the App, Settings → Privacy on the website, or privacy@nickelsense.com. We verify requests proportionately to their sensitivity using your signed-in account, or — for email requests — a verification code sent to the email address or phone number on the account, respond within the applicable statutory period, and explain your appeal rights if we decline. An authorized agent must provide written, signed permission from you, and we may ask you to confirm your identity directly with us. We honor the Global Privacy Control (GPC) signal for legally required opt-outs.
No penalty for declining. We will not charge you more or reduce your access because you declined optional analytics, research, or AI training, or because you exercised a right — except where law expressly permits a proportionate difference directly related to the value of the data and we give you the required notice.
The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has an account, contact privacy@nickelsense.com. We will investigate, restrict access, and delete information as required. If you indicate during signup that you are under 18, we stop the signup and do not keep the information you entered.
The Service is intended for use in the United States only. Our systems and providers process data in the United States. Please do not use the Service from another country unless we have published a country-specific supplement that permits it. If we later permit international use, we will implement the transfer safeguards required by applicable law (such as Standard Contractual Clauses) and a local supplement and publish Annex B.
We will post changes with a new effective date and version number, and give advance in-app and email notice of material changes. Before a new or materially different consumer-health-data purpose, research use, disclosure, or AI-training use, we will obtain fresh consent where required — we will not quietly widen an existing policy to cover a new use. Archived versions are available at archive.html.
Nickelsense Privacy Team
Nickelsense Inc.
Louisville, Kentucky
privacy@nickelsense.com · Settings → Privacy (in the App or on the web)
Appeals: appeals@nickelsense.com
You may also complain to the regulator or Attorney General with jurisdiction over you.
In the preceding 12 months, we collected the categories of personal information listed in Section 4, for the purposes listed in Section 6, and disclosed them to the categories of recipients listed in Section 16.
Nickelsense may not currently meet the thresholds to be a "business" under the California Consumer Privacy Act. We nonetheless provide the notice and rights in this Annex to California residents. We do not sell or share personal information as those terms are defined in the CCPA. We retain each category as described in Section 17. Sensitive personal information is used only for providing the Service you request, security and integrity, and other purposes permitted under Cal. Code Regs. tit. 11, § 7027(m).
California residents may exercise the rights in Section 22 at Settings → Privacy or privacy@nickelsense.com (because the Service is offered only online and we have a direct relationship with you, we accept requests by email instead of a toll-free number).
| Choice | What it permits | Where you make or change it | Effect of declining |
|---|---|---|---|
| Terms acceptance | The contract; core Service processing | Signup checkbox | Cannot use the Service |
| Consumer health data collection consent | Collecting recovery and mental-health fields where a state law requires separate consent | Intake, just in time | That optional field or feature is unavailable |
| Consumer health data sharing consent | Sharing with a named recipient category | Privacy center | No sharing |
| Signed authorization for sale | Any statutory "sale" | Separate signed form | None occurs |
| Cookie and tracking preferences | Functional media, optional analytics technologies | Settings → Privacy → Cookies and tracking | Essential only; all core features work |
| Product analytics opt-in | Section 12 events under a revocable token | Privacy center | No effect on features or price |
| Research consent | Section 13 data under an independent token | research-consent.html | No effect on features or price |
| AI/ML training opt-in | Only the categories checked in Section 14 | ai-training.html | AI features still work normally |
| Device permissions | The specific device capability | Device settings | Only that feature stops |
| Marketing communications | Promotional email or push | Notification settings | Service notices still sent |
| Recording consent | A specific recording, before it starts | In-session prompt | No recording |
Rule: no item in this table may be bundled with, or made a condition of, any other item.
Other legal documents
Nickelsense Inc. · Louisville, Kentucky · legal@nickelsense.com · (502) 354-8105