Version 1.0.1 · Effective July 28, 2026

Just For Today Consumer Health Data Privacy Policy

Effective July 28, 2026 · Version 1.0.1

This is a standalone policy from Prime Logic Labs LLC (a Virginia limited liability company) covering consumer health data in Just For Today. It exists because recovery data is health data — the most sensitive kind — and because laws like the Washington My Health My Data Act and the Maryland Online Data Privacy Act rightly demand a dedicated, specific policy for it. We apply these protections to every Just For Today user in every state, not just where a statute makes us.

Where this policy overlaps with our general Privacy Policy, the stronger protection here controls.

Honest framing, before anything else: Just For Today is a peer-support tool, not a healthcare provider. We are not covered by HIPAA, and we will never imply your data has HIPAA protection or legal confidentiality it doesn't have. What you do have is this policy — a binding promise about exactly what we collect, why, and your absolute right to take it back.

1. The consumer health data we collect

We collect only the health data you choose to give us, and here is the exact list:

  • Recovery status — the fact that you are in recovery (which using Just For Today implies) and related profile settings.
  • Sobriety date — your start date, and the derived counts built from it (days, streaks, lifetime totals).
  • Substance tags — the substance(s) you tell us you're recovering from (e.g., alcohol, opioids, nicotine), used to tailor content like body-healing cards.
  • Check-in details — optional mood ratings, gratitude lines, trigger notes, and daily wins you attach to a check-in.
  • Your "why I started" letter — the private letter written at onboarding.
  • Slip events — dates and optional reflections you record about a slip, and whether you chose to show them on your timeline.

Related data that can reveal health information — journal and journey responses, urge/trigger logs, "Need a Boost" usage, and recovery content you post to the community — is treated as consumer health data under this policy too. [ATTORNEY REVIEW: Virginia SB 754 — confirm the treatment and scope of free-text journal entries and journey responses as consumer health data under Virginia's framework.]

Sources: all of this comes from you, directly, in the app. We do not collect health data from third parties, data brokers, other apps, or inference engines.

2. Your consent comes first — before collection

We ask for your separate, specific, opt-in consent for health data before we collect any of it — at the sobriety-date step of onboarding, on its own screen, in plain language, unbundled from the Terms of Service and from anything else. It is not pre-checked, it is not buried in another agreement, and declining it still lets you use the non-health parts of the app.

  • Consent to collect is one decision.
  • Consent to share would be a separate decision — a distinct, additional opt-in we would have to ask for independently. We don't ask, because we don't share your health data with anyone except the processors in Section 5 acting on our instructions. If that ever changed, nothing would move without a new, separate, specific consent from you — never bundled, never assumed.

We record the version and timestamp of every consent so both of us have proof of exactly what was agreed.

3. Why we collect it (and nothing else)

Your health data is collected and used only to provide the features you're using it for:

  • Showing your day counts, streaks, heatmap, timeline, and milestones.
  • Personalizing affirmations, healing cards, and boost content to your substance tags and progress.
  • Computing your private stats (money saved, time reclaimed, mood trends).
  • Rendering share cards or videos you explicitly ask to create.

We limit collection and use to what is necessary for the features you've asked for. [ATTORNEY REVIEW: Maryland "strictly necessary" analysis — confirm each collection/use above satisfies MODPA's strictly-necessary standard, and document the analysis per data element.]

We do not use your health data for advertising, for training third-party AI models, for research without separate explicit consent, or for any purpose not listed here.

4. What we will never do with your health data

  • We will never sell your consumer health data. Not for money, not for "other valuable consideration," not ever. (Under Washington law a sale would require a signed authorization; we will simply never ask for one.)
  • We will never share it with advertisers, data brokers, insurers, employers, or law enforcement absent valid compulsory legal process.
  • No advertising or third-party analytics code runs on health surfaces. Screens that display or collect health data contain no ad SDKs, no tracking pixels, no third-party analytics, and no social-media embeds. Our analytics are self-hosted on our own servers, and health-data details are excluded from event payloads.
  • We will never use geofencing around care facilities. We do not create geofences around treatment centers, clinics, meetings, or any facility that provides health care services — not to identify you, not to track you, not to send you messages, not for anything. (Our optional milestone-location feature is you typing a place onto your own memory; it involves no geofence and no background location.)

5. Who processes it for us

These service providers process data on our infrastructure's behalf, under contracts (including MHMDA-compliant processor terms) that restrict them to acting on our documented instructions and bind them to this policy's limits:

Processor Role
[HOSTING PROVIDER PLACEHOLDER] Cloud hosting of our servers, database, and encrypted file storage
[EMAIL PROVIDER PLACEHOLDER] Delivery of login codes and service email (message metadata only)
[PUSH PROVIDER PLACEHOLDER] Delivery of push notifications you opt into (notification content is written to reveal nothing sensitive)

[ATTORNEY REVIEW: finalize the processor list, execute processor agreements, and confirm the notification-content review before launch.] We do not share consumer health data with any affiliates. When this list changes, we will update this policy and its version number — never silently.

6. Your rights over your health data

Every user, in every state, can at any time:

  • Know and access — see what health data we hold about you and get a copy (Settings → Export, or email us). This includes a list of the third parties (Section 5) it has been disclosed to.
  • Withdraw consent — stop our collection and use of your health data going forward, without deleting your account. Withdrawing consent turns off health features but never punishes you: no lost account, no lost non-health content, no degraded basic service.
  • Delete — absolutely. Ask, and we delete your consumer health data (or your whole account) — a hard delete, not a flag:
    • Removed from our live systems within 30 days of your verified request (we aim for much faster; in-app deletion begins immediately).
    • Purged from encrypted backups as they rotate, within 6 months at the outside. Backups are restore-only until then; if a backup containing deleted data were ever restored, the deletion is re-applied.
    • Propagated to the processors in Section 5, whom we instruct to delete as well.
    • Community content: posts and messages you authored are deleted or de-identified along with your account. [ATTORNEY REVIEW: MHMDA deletion mechanics for community content — quoted/replied copies of a deleted user's words in other users' threads, and deletion-vs-integrity handling for shared spaces.]
  • Appeal — if we ever decline a request (for example, a narrow legal-retention duty), we'll explain why in writing, and you can appeal by replying to that decision; we'll answer your appeal within 45 days. If you're still unsatisfied, you may contact your state Attorney General.

Exercising rights is free, requires only that we can verify it's really you (via your logged-in session or your account email), and never results in retaliation, discrimination, or a worse service.

7. Security

Health data is encrypted in transit and at rest. Internal access is restricted to the minimum staff needed to operate the Service, protected by role-based controls, and logged. Share cards and public pages only ever include what you explicitly chose to share.

8. Changes to this policy

We will not weaken a protection in this policy by silently posting a new version. Changes come with advance in-app or email notice; material changes — anything touching collection, sharing, sale, or deletion — require your renewed consent before they apply to your data. Every version is archived, hashed, and available to you.

Questions? legal@primelogiclabs.example

Just For Today Consumer Health Data Privacy Policy — version 1.0.1 — effective 2026-07-28