Anchor & Ascent

Privacy Policy

Effective date: July 14, 2026

This Privacy Policy explains what information Anchor & Ascent ("we," "us," "our") collects through the Service, how it's used, how it's protected, and your rights regarding that information.

Important: our role as a data processor. For information about an organization's residents and staff, the organization using the Service (for example, a sober living operator) is the one deciding what to collect and why — we host and process that data on their behalf. If you're a resident or staff member of one of our customer organizations and have questions about your own information, your first point of contact should be that organization, not us directly.

1. Information we collect

From the organization and its staff/admin users (our direct customers):

  • Account information: name, email, role, organization name.
  • Billing and contact information for the organization itself.
  • Usage data and audit logs: general activity needed to operate and secure the Service (e.g. who changed what).

Entered by the organization about its residents and staff (on the organization's behalf, not collected by us directly):

  • Identity and contact information (names, addresses, phone numbers).
  • Housing and billing records (charges, payments, bed/house assignment, move-in/move-out dates).
  • Case management records: behavioral notes, goals, chores, curfew check-ins, progress notes.
  • Sensitive information: drug test results, incident/behavioral documentation, uploaded files, and signed documents.

Automatically:

  • Standard technical data (IP address, browser/device information, timestamps, access logs) for security, troubleshooting, and audit purposes.

2. How information is used

  • To provide and operate the Service for the organization that entered it.
  • To secure the Service (e.g. audit logging, fraud/abuse prevention, breach response).
  • To communicate with organization admins/staff about their account, service updates, and billing.
  • We do not sell personal information.

3. Who we share information with

Sub-processors that host or process data on our behalf as part of running the Service: Supabase (database, authentication, file storage), Vercel (application hosting), Stripe (payment processing), and Resend (account and notification email). Each subprocessor's data processing practices are covered under their standard Data Processing Addendum or Terms of Service, available on request. We'll give you reasonable advance notice before adding a new subprocessor that will process your organization's data.

Data isolation: we do not share resident or organization data across organizations — each organization's data is completely isolated from every other organization's by the Service's design, with the narrow exception of the platform administrator role described below.

Platform administrator access: a small number of individuals responsible for operating the platform itself can see organization-level information across all organizations — organization name, resident/staff counts, plan, and billing status — for the purpose of running the business. This access does not extend to resident-level records (names, notes, drug test results, documents, or other sensitive files) inside any organization's account. Administrator access is logged.

We may disclose information if required by law (e.g. a valid subpoena or court order), and would typically notify the affected organization first unless legally prohibited from doing so.

4. Data security

  • Each organization's data is isolated from every other organization's through database-level access controls (Postgres Row Level Security), not just application-level checks — verified by an automated test suite run before every release.
  • Sensitive files (signed documents, uploaded attachments, profile photos) are stored in access-controlled storage, not publicly accessible by default.
  • Changes to key records are logged in an audit trail.
  • Data backups are taken daily and retained for a minimum of 7 days.
  • Data is encrypted in transit (HTTPS).
  • We have not obtained a third-party security certification (such as SOC 2); nothing here should be read to imply one. No system is perfectly secure, and we don't guarantee the Service will be free of vulnerabilities, interruptions, or data loss.

5. Data retention

We retain organization data for as long as the organization's account is active. After an organization closes its account, you can request an export of your data for 7 years, after which it is deleted.

You are responsible for determining whether your organization must retain data longer than 7 years under applicable law. This may include HUD requirements for federally-funded housing programs (7-year minimum), state housing or behavioral health record laws (some states require longer), HIPAA if applicable (generally 6 years from the last patient encounter), 42 CFR Part 2, CCPA/CPRA, and other state privacy statutes. We retain data according to this 7-year policy; you remain solely responsible for your own compliance with any stricter retention requirement that applies to your organization.

Signed documents and financial records may be retained longer where needed for legitimate business, audit, or legal record-keeping purposes.

6. Your choices and rights

  • Organization admins can access, export, and delete most records they've entered through the Service directly.
  • Depending on where your organization and its residents are located, you or your residents may have rights to access, correct, delete, or port personal information under state privacy laws — including California's CCPA/CPRA and similar laws now in effect in a growing number of other states.

Submit requests to support@anchorandascent.app. We'll respond within 45 days or as required by applicable law.

7. Children's privacy

The Service is intended for use by adult residents and staff of housing programs. We do not knowingly collect information about minors. If a customer organization serves minors, that organization is responsible for ensuring appropriate parental consent and compliance with applicable children's privacy laws.

8. HIPAA and 42 CFR Part 2

The Service is not designed, intended, or certified for HIPAA compliance. HIPAA applies only if your organization is a HIPAA covered entity or business associate. If that applies to you, you must tell us before submitting any protected health information, and the parties will work in good faith to put a Business Associate Agreement in place before that information is submitted — see the Terms of Service, Section 10.

42 CFR Part 2 (federal substance abuse confidentiality regulations) applies only to programs that hold themselves out as providing substance abuse diagnosis, treatment, or referral and are federally assisted. Housing-only programs that provide housing and peer support without clinical services typically fall outside both HIPAA and Part 2, but state-specific confidentiality laws may still apply — consult your own legal counsel to confirm your organization's status.

9. Limitation of liability

Our total liability for any claim related to this Privacy Policy or our handling of your data is limited to $500 per customer, as described in the Terms of Service, Section 12. We are not liable for indirect, incidental, special, consequential, or punitive damages related to data handling or privacy matters.

10. Changes to this policy

We may update this Privacy Policy from time to time. Organization administrators will be notified by email, and the effective date above will be updated.

11. Contact

Questions about this Privacy Policy, or requests regarding your information: support@anchorandascent.app.

See also our Terms of Service.