Privacy Policy
Effective Date: July 25, 2026
This policy explains how CommonHelpSource handles information when you use commonhelpsource.com. The tools provide educational and workflow support; they are not emergency services, medical care, legal advice, or a substitute for professional judgment.
1. Information We Collect
- Information you submit: assessment answers, ZIP code, tool prompts, and contact-form messages.
- Technical information: IP address, browser and device information, referring page, access time, and diagnostic logs that our hosting and security providers may process.
- Cookie and advertising information: choices and identifiers described below when advertising or analytics features are enabled.
What is removed from free text
Before free-text narrative is sent to our automated language-generation provider, CommonHelpSource removes high-confidence direct identifiers such as explicitly labeled client or patient names, dates of birth, Social Security numbers, and supported medical-record, insurance, or account numbers. Ages of 90 and over are aggregated. The check runs in the browser and again on the server immediately before external processing. Do not intentionally enter direct identifiers, because automated removal can miss unusual or indirect identifying details.
What is deliberately kept, and why
ZIP codes, dates of service or contact, and the addresses and phone numbers of the organizations we refer you to are not removed. These are what make the tool work: a ZIP code is how we match you to organizations that actually serve your area, a date of contact is what makes a progress note accurate, and an agency's phone number is what lets you make contact. None of these identify an individual on their own.
What is stored
CommonHelpSource does not save assessment or progress-note narrative to its application database as a client record. The application processes it in memory to produce the requested result. The language-generation and hosting providers still process requests under their own API privacy, security, logging, and retention terms. After each generation we show a compact privacy check listing the categories and counts of information removed; it never repeats the removed values.
Automated removal is a risk-reduction safeguard, not a guarantee of HIPAA de-identification. It may miss unusual names, nicknames, indirect identifiers, rare events, or combinations of facts that identify a person. Do not intentionally enter direct identifiers, review the privacy preview and the final report, and follow your employer's privacy, authorization, and security requirements.
2. How We Use Information
We use submitted information to generate the result you request, locate relevant resources, operate and secure the site, troubleshoot errors, respond to messages, and improve the tools.
CommonHelpSource also records a small set of first-party aggregate events, such as a page view, a tool starting, a tool succeeding or failing, and a click to a major site area. These events contain only an event category, a broad page category, and the server time. They do not contain assessment answers, prompts, ZIP codes, names, full URLs, referral details, cookies, or a persistent browser identifier.
To control automated use and service expenses, the service converts the connection IP address into a one-way daily hash and counts requests in hourly and daily windows. The rate-limit record does not contain the submitted assessment or narrative. The daily hash changes each day.
3. Automated Generation and Service Providers
Some planning and drafting tools use automated language-generation technology. Those tools send the answers or text you submit to a third-party language-generation provider so the requested result can be produced. Hosting, search, mapping, resource-directory, security, and form-processing providers may also process information as necessary to provide their services.
CommonHelpSource does not create a clinical record for you. However, service providers may retain request data or logs under their own terms, security practices, and retention policies. Because these tools are not presented as a HIPAA-covered workflow, do not submit protected health information or direct client identifiers.
4. Cookies and Advertising
CommonHelpSource may use Google AdSense or similar services on non-sensitive pages. Google’s certified consent management platform presents applicable regional choices and records advertising-consent decisions. Depending on your location and choice, advertising services may use cookies or similar technologies to measure ads or personalize advertising. Sensitive assessment and clinical-input pages are intended to remain free of advertising.
The AdSense ownership-verification code is present on the public homepage while the site is under review. Future ad placements are restricted in code to marked educational pages such as field guides and methodology pages, where Google’s CMP and advertising systems apply the user’s regional consent signal. They are blocked from assessments, results-oriented tools, professional drafting tools, case-management pages, and the group-session builder.
Where Google’s consent message applies, you can use the site’s “Privacy and cookie settings” control to reopen it and change your preference. You can also manage Google advertising personalization in Google My Ad Center.
5. Sharing and Sale
We do not sell the assessment answers or contact messages you submit. We share information with service providers as described above, when you direct us to do so, or when required to protect the service, comply with law, or respond to a valid legal process.
6. Retention and Security
We retain information only as reasonably needed for the purposes described here, subject to provider logs, backups, legal obligations, and security needs. No internet service can guarantee absolute security. Data minimization and de-identification are important safeguards.
First-party aggregate event records are scheduled for deletion after 90 days. First-party rate-limit records are scheduled for deletion after two days. Hosting, language-generation, form, and security providers may maintain separate logs under their own documented practices.
7. Children and Emergencies
The site is intended for adults and professionals and is not directed to children under 13. Do not use the contact form or a drafting tool for an emergency. Call 911 for immediate danger and call or text 988 in the United States for a suicide or mental-health crisis.
8. Your Choices
You may decline optional cookies, avoid submitting information, or request help concerning a contact submission. Browser controls may also block or clear cookies. Choices and legal rights vary by location.
9. Changes to This Policy
We may update this policy as the service changes. The effective date above identifies the latest revision.
10. Contact Us
For privacy questions or requests, use the contact form. Please do not include client information or sensitive health details.