Privacy Policy

Effective Date: August 3, 2026

This policy explains how CommonHelpSource handles information when you use commonhelpsource.com. The tools provide educational and workflow support; they are not emergency services, medical care, legal advice, or a substitute for professional judgment.

1. Information We Collect

What is removed from free text

CommonHelpSource assessments do not ask for a person's name or other identifying information. Do not enter names, dates of birth, Social Security numbers, addresses, personal phone numbers, or record, insurance, or account numbers. If identifying information is accidentally included in free text, CommonHelpSource removes high-confidence direct identifiers in the browser and checks again on the server immediately before AI processing. Ages of 90 and over are aggregated.

What is deliberately kept, and why

ZIP codes, dates of service or contact, and the addresses and phone numbers of the organizations we refer you to are not removed. These are what make the tool work: a ZIP code is how we match you to organizations that actually serve your area, a date of contact is what makes a progress note accurate, and an agency's phone number is what lets you make contact. None of these identify an individual on their own.

What is stored

CommonHelpSource does not save assessment or progress-note narrative to its application database as a client record. The application processes it in memory to produce the requested result. The AI and hosting providers still process requests under their own API privacy, security, logging, and retention terms. After each generation we show a compact privacy check listing the categories and counts of information removed; it never repeats the removed values.

Email-and-password accounts are managed by Netlify Identity. The sign-up and login forms pass the email address and password to Netlify Identity over HTTPS. CommonHelpSource does not write passwords to its application files, Netlify Blobs, logs, saved drafts, feedback records, or membership records, and administrators cannot retrieve a member's password from the CommonHelpSource application. After authentication, Netlify Identity issues signed session tokens that allow the site to recognize the member.

Automated removal is a risk-reduction safeguard, not a guarantee of HIPAA de-identification. It may miss unusual names, nicknames, indirect identifiers, rare events, or combinations of facts that identify a person. Do not intentionally enter direct identifiers, review the privacy preview and the final report, and follow your employer's privacy, authorization, and security requirements.

2. How We Use Information

We use submitted information to generate the result you request, locate relevant resources, operate and secure the site, troubleshoot errors, respond to messages, and improve the tools.

The public homepage displays a cumulative site-visit counter. Each page load adds one to a single aggregate number. The CommonHelpSource application does not store an IP address, cookie, browser identifier, page path, referrer, timestamp, or individual visit record for this counter. Reloads and automated visits may be included, so the number is not a count of unique people. Netlify still processes ordinary connection information as the site’s hosting provider under its own practices.

To control automated use and AI expenses, the service converts the connection IP address into a one-way daily hash and counts requests in hourly and daily windows. The rate-limit record does not contain the submitted assessment or narrative. The daily hash changes each day.

For signed-in Guided Planning Runs, CommonHelpSource records the member's internal account ID, tool category, model name, input-token count, output-token count, estimated AI cost, and time period. These operational records do not contain prompts, generated text, client details, saved drafts, or email addresses.

3. AI and Service Providers

Some tools send the answers or text you submit to third-party service providers, including an AI provider, so the requested result can be generated. Hosting, search, mapping, resource-directory, security, and form-processing providers may also process information as necessary to provide their services.

CommonHelpSource does not create a clinical record for you. However, service providers may retain request data or logs under their own terms, security practices, and retention policies. Because these tools are not presented as a HIPAA-covered workflow, do not submit protected health information or direct client identifiers.

Netlify provides hosting and account authentication. Stripe processes paid-membership billing when a person chooses a paid plan. If you separately request The 413 Brief, CommonHelpSource sends your email address and subscription-source information to Beehiiv so it can confirm and manage that newsletter subscription. Account creation alone does not authorize newsletter enrollment.

4. Cookies and Advertising

CommonHelpSource may use Google AdSense or similar services on non-sensitive pages. Google’s certified consent management platform presents applicable regional choices and records advertising-consent decisions. Depending on your location and choice, advertising services may use cookies or similar technologies to measure ads or personalize advertising. Sensitive assessment and clinical-input pages are intended to remain free of advertising.

The AdSense ownership-verification code is present on the public homepage while the site is under review. Future ad placements are restricted in code to marked educational pages such as field guides and methodology pages, where Google’s CMP and advertising systems apply the user’s regional consent signal. They are blocked from assessments, results-oriented tools, professional drafting tools, case-management pages, and the group-session builder.

Where Google’s consent message applies, you can use the site’s “Privacy and cookie settings” control to reopen it and change your preference. You can also manage Google advertising personalization in Google My Ad Center.

5. Sharing and Sale

We do not sell the assessment answers or contact messages you submit. We share information with service providers as described above, when you direct us to do so, or when required to protect the service, comply with law, or respond to a valid legal process.

6. Retention and Security

We retain information only as reasonably needed for the purposes described here, subject to provider logs, backups, legal obligations, and security needs. No internet service can guarantee absolute security. Data minimization and de-identification are important safeguards.

The cumulative site counter is retained as one aggregate number. First-party rate-limit records are scheduled for deletion after two days. Product-feedback submissions are scheduled for deletion after 18 months, and aggregate member AI-usage cost records are scheduled for deletion after 13 months. Hosting, identity, AI, form, billing, and security providers may maintain separate records under their own documented practices.

7. Children and Emergencies

The site is intended for adults and professionals and is not directed to children under 13. Do not use the contact form or an AI tool for an emergency. Call 911 for immediate danger and call or text 988 in the United States for a suicide or mental-health crisis.

8. Your Choices

You may decline optional cookies, avoid submitting information, or request help concerning a contact submission. Browser controls may also block or clear cookies. Choices and legal rights vary by location.

You may unsubscribe from The 413 Brief through the link in any newsletter without losing your CommonHelpSource account or free-tier access.

9. Changes to This Policy

We may update this policy as the service changes. The effective date above identifies the latest revision.

10. Contact Us

For privacy questions or requests, use the contact form. Please do not include client information or sensitive health details.