Privacy policy
Last updated August 2026
Draft — pending attorney review
This document describes how the platform actually works, but it has not been reviewed by counsel and is not yet in force. It must not be published as final, and it is not legal advice.
Who this covers
Living Sobriety provides software to recovery residence operators. Two groups use it: operators and their staff, and residents of the houses those operators run.
For resident information, the operator decides what is collected and why. We process it on their behalf and under their instructions.
What we collect
About residents: name, email address, phone number, date of birth, emergency contact, which house and bed they occupy, their move-in and move-out dates, the charges and payments on their account, any notes staff add, and the documents they sign.
About staff: name, email address, role, and which houses they can see.
Automatically: sign-in attempts including failures, network address, and browser, used for security and for the audit trail described below.
What we deliberately do not collect
We do not store drug or alcohol test results, treatment or clinical notes, incident reports, or meeting attendance. That boundary is a design decision, not an oversight: those records carry federal substance-use-disorder confidentiality obligations that would attach to the whole system holding them.
We also never see full payment card numbers or bank credentials. Those go directly to our payment processor. We keep only the card brand, the last four digits, and the expiry date.
Who can see what
Access is limited by role and, for staff, by house. A house manager scoped to one house cannot see residents of another. Staff whose job is billing can see charges and payments and the financial agreement, but not other signed documents or personal notes.
Operators cannot see each other's data. There is no shared directory and no cross-operator resident history.
Our support staff can see organization and system health, not resident records. Reading a resident record requires a time-limited elevation with a stated reason, it is logged, and the operator can see that it happened.
The audit trail
We record who viewed a resident record, who downloaded a document, who exported a report, who changed permissions, when consent was given, and failed sign-in attempts. The log cannot be edited or deleted by any user, and it is chained so that alteration is detectable.
You can ask to see the trail of what was done to your own record.
Who we share it with
Only the service providers needed to run the platform: our hosting and database provider, our payment processor, our email provider, our error monitoring service, and our address lookup provider. Each processes data only to provide that service.
We do not sell personal information, and we do not share it for advertising.
How long we keep it
Records are retained while an account is active and afterwards as needed for financial, contractual, and legal obligations. Signed documents are retained deliberately: an electronic signature is only enforceable if the signed record can still be produced.
You can request deletion of your information. We record every request and respond with what can be removed and what has to be kept, and why. Signed agreements and audit records generally have to be kept.
Security
Data is encrypted in transit and at rest. Signed documents live in private storage and are served only through short-lived links after an authorization check. Staff and administrator accounts require two-factor authentication.
Contact
Residents: your recovery residence is the first point of contact for questions about your information. You can also contact us directly, and we will work with them.